← All articles

ENTERPRISE NETWORKING · 19 SEPTEMBER 2026

Enterprise VLAN and switch handover: a service-matrix worksheet

A managed switch showing green link lights is not a completed enterprise network. The buyer needs a traceable record of which business service uses each VLAN, where that VLAN is permitted, how devices receive addresses, what communication is intentionally allowed, and how the configuration can be recovered.

Start with services, not VLAN numbers

List the operational groups before assigning IDs: staff, guest access, CCTV, access control, voice, building management, servers, switch management and any tenant or operator handoff. For each group, record its owner, device types, addressing method, gateway, DNS and time services, internet requirement, internal destinations and explicit restrictions.

Cisco's network-segmentation overview defines segmentation as dividing a network into smaller parts and controlling traffic between them. A VLAN alone creates a logical segment, but the security outcome also depends on routing, firewall or access-control policy, switch management and the accuracy of port assignments.

Service row: service name · business owner · VLAN ID and name · IPv4/IPv6 subnet · gateway · DHCP or static addressing · DNS/NTP · permitted destinations and ports · blocked destinations · internet policy · authentication method · criticality · acceptance approver.

Map every edge port and uplink

Record each switch by hostname, location, model, serial number, management address and rack position. For every active interface, capture the patch-panel and outlet reference, connected device, access VLAN or trunk role, PoE requirement, speed and duplex policy, description and shutdown state. Unused ports should have an agreed administrative state and documented activation process.

For every trunk, record both endpoints, allowed VLAN list, native VLAN decision, link aggregation membership and expected redundancy behavior. The current Cisco VLAN configuration guide identifies native-VLAN mismatch as a common trunk misconfiguration that can misdirect traffic or create security exposure. Do not rely on the two switch configurations merely looking similar; verify the operational state from both ends.

Use one controlled source of truth

The approved service matrix, switch-port schedule and network diagram should agree. A useful handover package includes the logical topology, rack and patching diagram, IP plan, VLAN list, trunk matrix, gateway and DHCP ownership, policy summary, switch inventory, software versions, configuration backups and change log. Store credentials separately using the owner's approved secure process; do not place passwords in a general handover PDF.

Mark whether each configuration backup was taken before or after the final acceptance changes, how it can be restored, and who owns future changes. A backup that has never been checked for completeness should be recorded as unverified.

Acceptance tests should follow the service matrix

  1. Port identity: connect at a sampled outlet and confirm the expected switch interface, VLAN, address source and gateway.
  2. Allowed communication: verify the device can reach each approved destination using the required application or test method.
  3. Denied communication: verify representative prohibited paths fail as designed. A ping alone does not prove that an application policy is correct.
  4. Infrastructure services: confirm DHCP, DNS, NTP and any authentication or controller dependency from the intended segment.
  5. Trunk consistency: compare allowed and native VLAN settings at both ends and confirm the expected VLANs are forwarding.
  6. Resilience: where redundancy is in scope, run an approved maintenance-window test and record traffic impact and recovery time. Do not disconnect production links without authorization.
  7. Operations: confirm monitoring, time synchronization, configuration backup, log destination and the process for enabling a spare port.

Record evidence, not a blanket pass

Acceptance line: test ID · date/time · source outlet and device · source VLAN/address · destination/service · expected result · observed result · switch/interface · evidence reference · tester · owner witness · exception and closure date.

Repeat tests after material configuration changes. Where a security policy is managed by another contractor or customer team, state the boundary clearly and attach their approval rather than marking the whole network as verified by one party.

Related reading: use the campus Wi-Fi design and acceptance worksheet for coverage, roaming and wireless capacity decisions. For project scope, see enterprise networking services.

Planning a managed network for a building or campus?

Share the floor plans, service groups, outlet schedule and security requirements. We can develop the BOQ, switching plan, rack integration, commissioning tests and handover records around the actual site.

Discuss the network ↗