IP plan
Which range serves which purpose, where static addresses begin and where the assignment pool ends. In networks that grew without a plan, overlapping ranges and untouchable static addresses pile up.
Drawn first, built second. The IP plan, VLAN scheme and physical layout reach you before anything is installed.
Most of the networks we meet in the field were never designed; they grew as needs appeared. A modem arrived first, then a switch when headcount rose, then an access point when wireless was requested, then a second one when guests complained. Each step is reasonable on its own. What exists five years later is a structure nobody can draw, where nobody knows which cable goes where, and where every intervention is a gamble.
Network design replaces that accumulation with a planned structure. Our first rule in corporate network deployment is straightforward: a network is not built before it is drawn. Before any device is ordered, the IP plan, the VLAN scheme and the physical layout are put on the table as documents. No hardware is purchased until they are approved — because buying the right device for a badly designed network is the most expensive way to spend the budget.
A network design has deliverables you can hold. "We have a plan in mind" is not a design.
Which range serves which purpose, where static addresses begin and where the assignment pool ends. In networks that grew without a plan, overlapping ranges and untouchable static addresses pile up.
Staff, guests, servers, cameras and production devices in separate segments. Which segment may reach which is written into a table before deployment, and every later exception is recorded there.
Cabinet locations, cable routes, access point positions and the labelling convention. The goal is simple: not a single unlabelled cable left in the rack.
Of the three, the IP plan is the one most often skipped and the one that costs the most. In networks that grew without a plan, addresses were handed out from whichever range came to mind that day. A few years later, when two branches need to be joined, it turns out the same range is in use at both sites and the link between them fails for reasons of design rather than equipment. In the same way, static addresses accumulate with no record of who assigned them or why; nobody dares touch them because nobody knows which device would stop.
The VLAN scheme, meanwhile, is the physical counterpart of security policy. On a network where a guest device can see the finance server, what is written in the firewall matters rather less. Keeping cameras, payment terminals and production equipment in their own segments is decided at design time for the same reason — adding segmentation later means splitting a live network, and that always costs downtime.
The output of a survey is a report rather than a quotation: what stays, what changes, and the reason for both. That report remains yours even if you do not continue with us.
The most common mistake in network design is sizing for today. A forty-eight port switch is more than enough for thirty users now; three years later, with fifty users, two printers, eight cameras, a few meeting room displays and the handheld terminals in the warehouse, the same switch is full. What happens when it fills is predictable: an unmanaged desktop switch appears under a desk somewhere, and the day it does the network stops being observable.
Port count, cabling, cabinet space and power capacity are therefore planned against a three-year projection. Headroom matters most in cabling, because pulling cable afterwards is the most expensive and most disruptive part of the job: ceilings come down, trunking is opened, the office fills with dust. A few spare runs pulled during the original deployment cost almost nothing next to the same runs pulled three years later.
The same arithmetic applies to power. Where access points and cameras are fed over the data cable, the switch power budget has to be calculated up front; a device chosen at the margin will quietly stop delivering power once a few more cameras arrive. UPS capacity is likewise sized against how long it must keep the whole network up — a network that dies in a power cut also renders the protected server useless.
Devices are replaced; cable stays. The layer that receives the least attention is the one that deserves the most.
A switch is replaced in five years, a firewall in three; cable stays for ten. That is why cabling decisions follow the next decade rather than the present headcount.
Both ends of every run are labelled with the same convention and recorded on the rack diagram. In an unlabelled cabinet a simple port move takes half an hour; in a labelled one, two minutes.
Every run is tested and the result goes into the handover file. A marginal cable does not fail outright — it produces a connection that drops occasionally and whose cause is never found.
Cable management, unit placement, ventilation and earthing. A messy cabinet is not merely ugly; it produces thermal problems and cables pulled loose by accident.
Signal reaching everywhere and everyone working comfortably are not the same outcome. The real question in wireless design is not where the signal lands but how many devices are doing what at once.
Cabling an empty building is easy. The difficult work is renewing the network of an organisation that operates every day without moving it off its feet. That is why the migration plan is inseparable from the design.
Every stage has a deliverable; a stage without one is not finished.
Inventory, cabling, coverage and traffic profile are captured. The output is a report: what stays, what changes, and why.
IP plan, VLAN scheme and physical layout are drawn. They reach you as documents before deployment, and no hardware is ordered until they are approved.
Device selection follows the design. Cabling, labelling and rack build are completed at this stage and every run is tested.
Devices are staged first, then brought into service to plan. Steps requiring downtime move out of hours and the rollback path stays open.
Diagram, IP plan, configuration files, link test results and passwords are handed to the organisation, along with the post-deployment coverage survey.
The most practical way to judge a network deployment is this: if the team that built it disappeared tomorrow, how many days would it take a newcomer to become effective? In an undocumented installation the answer is measured in weeks, most of them spent tracing cables and hunting for device passwords.
The handover file is therefore part of the job rather than an extra to be requested later. It contains the network diagram, IP plan, VLAN table, device inventory, configuration files, link test results, coverage survey reports and passwords. Passwords are handed to a nominated officer of the organisation and can be changed by them — we never keep access to ourselves after a deployment.
There is a commercial consequence to this: we do not lock clients in through missing documentation. Taking ongoing network management from us should be a choice, not a necessity. Where it does continue, the documents produced during design become the foundation for monitoring, rule writing and capacity planning.
Survey and design take a few days in a small office and one to two weeks in a multi-storey hotel or factory. The item that really drives the deployment schedule is cabling: if existing cabling can be reused, a week may be enough, while pulling cable from scratch in a difficult building can stretch the work to three to six weeks. The schedule is given step by step alongside the survey report.
Usually a good part of it stays. The survey report assigns each device one of three outcomes: stays as is, stays with a different configuration, or has to be replaced. Where replacement is required the reason is written down as well — not manageable, not enough ports, end of vendor support, or no longer receiving security updates. We do not replace a working device merely because it is old.
The aim is that it does not. Devices are staged during business hours and only the cutover steps produce downtime, which is scheduled out of hours. For critical infrastructure the old and new setups run in parallel for a period. How much downtime each step produces is written into the migration plan in minutes, and each step keeps a rollback path ready.
Structured cabling is part of the design. Route planning, cable category selection, rack layout, labelling convention and termination are ours. The physical pulling of cable is carried out together with regional crews, while responsibility and testing remain with us. Every run is tested and the result goes into the handover file.
A signal level map against the floor plan, interference from neighbouring networks, channel usage, and an estimate of clients per access point. The survey is run twice: once before deployment to record the starting point and once after to record what was achieved. Both reports are handed over together, so what the deployment changed is not open to debate.
Yes, and we work in a way that makes it possible from the start. The network diagram, IP plan, VLAN table, configuration files, link test results and all passwords are handed to the organisation. We do not tie anyone in through missing documentation; whether an incoming team can do the job on day one is the measure of the handover file.
The design follows the three-year projection rather than today's headcount. If there are thirty users today and fifty are expected in three years, port count, cabling, cabinet space and power are planned accordingly. Pulling cable later is the most expensive part of the job, so a spare run left in place during deployment costs almost nothing next to the same run pulled three years from now.
We split the work in two. Survey and design are a separate fixed-fee item whose output — a report and a set of diagrams — stays with you even if you do not continue with us. Deployment is quoted once the design is approved, with hardware and cabling itemised openly. Equipment cost and labour appear on separate lines, and the reason each device was chosen is written down.
Related services
The parent page covering every network service from design and security to deployment and ongoing management.
Measuring the network once built: threshold design, alert flow, capacity reporting and monthly management.
Turning the VLAN and routing scheme drawn during design into working device configuration.
Post-deployment support covering workstations, servers and printers from the same desk.
Planning the link between local servers on the new network and hosting outside the building.
Book a free 30-minute discovery call with our team.
Our network and cyber security work is carried out by a team holding internationally recognised Cisco certification.
Issued by Cisco · Holder: Devrim Tunçer
A certification covering security operations centre (SOC) competency: security monitoring, incident response and analysis of network attacks. It is the foundation we rely on for intrusion detection, log correlation and post-incident response work.
Cisco training certificate · completed January 2023
Covers networking fundamentals: routing, switching, IP addressing and network security. The knowledge base we draw on for enterprise network setup and segmentation.