Small Business Coffee Shop Network Design
Network Infrastructure Design and Security · Cisco Packet Tracer
Problem Statement
A small coffee shop needed reliable connectivity for staff, secure business devices, and public Wi-Fi — without letting guest users touch internal systems.
Objectives
- Segment internal traffic from guest traffic
- Centralize IP management with DHCP
- Secure device configuration
- Scalable architecture for future growth
Architecture
Router
│
Switch (Trunk)
├── VLAN 10 · Admin/Internal ── POS, Admin PCs, Mgmt
└── VLAN 20 · Guest Wi-Fi ──── AP → Customer devices
Implementation
- IPv4 subnetting from 172.16.0.0/16 pool
- VLAN 10 (Admin) & VLAN 20 (Guest) with trunk links
- Static IPs for routers, switches, APs
- DHCP for endpoints to eliminate config errors
- Device hardening & secure management
Security Principle
"Do not allow every device on the network to communicate with every other device by default."
Segmentation reduced attack surface and blocked lateral movement from guest devices.
Results
- 2 VLANs isolating trusted vs untrusted users
- 10+ endpoints served via DHCP
- Working inter-VLAN routing & trunking
- Foundation for investigating network-based alerts