Network segmentation case study
Current Infrastructure Environment
Separating store operations from office systems without interrupting the production resources the business still depends on.
Existing network layout
During my time managing the environment, one of the largest technical issues I identified was that the production and office environments had never been properly separated.
The infrastructure contains two logical networks: production and office. In practice, nearly every device has historically been placed on the production network regardless of its purpose.
Production network
Historically carried both operational and office devices.
- Point-of-sale and self-checkout systems
- Office workstations and laptops
- Production and office printers
- Shared business resources
Office network
Available, but largely unused.
The presence of a second network did not create meaningful separation because office equipment remained inside the production environment.
The objective
The long-term objective is a clear boundary between systems that operate the store and systems used for ordinary business work. Production should contain only what store operations require; laptops, office desktops, office printers, the plotter, security administration, and shared documents should reside on the office network.
This separation reduces unnecessary exposure of production systems and allows office equipment to be managed independently.
The dependency that sets the pace
The largest constraint is the LOC SMS environment. Office users should not reside on the production network, but several of their workflows still depend on production databases and applications.
The migration cannot be treated as a simple VLAN move. Office systems need a controlled path back to the specific production resources their work requires.
Solutions implemented
eSuite
The organization purchased eSuite through Ravyx to provide remote access into portions of LOC SMS. It is useful, but it does not yet replace every workflow performed directly against production systems.
Linux gateway
I repurposed an HP workstation, installed Linux Mint, placed it on the production network, and configured it as a Tailscale subnet router. Authorized office computers can now reach required production resources through Tailscale without residing directly on the production network.
- Office systems can move away from production.
- Required production resources remain accessible.
- Office devices no longer inherit every production-workstation restriction.
- The office environment can expand without enlarging the production network.
- Office network
- Employee computers and office equipment move here.
- Controlled paths
- eSuite provides access to portions of LOC SMS. Tailscale connects authorized devices to the Linux Mint subnet router.
- Production network
- The router reaches required LOC SMS resources while POS, self-checkout, production printers, and scanners remain local to production.
Current infrastructure inventory
Production
- POS checkout lanes
- 7
- Self-checkout stations
- 4
- Back-office terminals
- 3
- Production printers
- 2
- Linux Mint subnet router
- 1
- Zebra handheld scanners
- Deployed
- Mobile inventory scanners
- Deployed
Office
- Laptops
- 6
- Desktop workstations
- 3
- Office printers
- 3
- Large-format plotter
- 1
- DVR/security system
- 1
- Shared file resources
- Transitioning
Remaining work
The high-level architecture is understood. A successful migration now depends on documenting every operational dependency so that each move can be repeated, verified, and reversed if necessary.
- Printer mappings
- Network shares
- Software licensing
- Database connectivity
- Scanner integrations
- Application dependencies
- Authentication methods
- Backup procedures
Completing this dependency record would turn the current architecture into a repeatable migration plan and reduce operational risk during future infrastructure changes.