A badly configured business network can cost as much as €50,000 a year in lost productivity. Is your infrastructure up to it?
Why do you need Wi-Fi 6?
Wi-Fi 6 (802.11ax) brings significant improvements:
- Speed: up to 9.6 Gbps (vs 3.5 Gbps on Wi-Fi 5)
- Capacity: 4× more simultaneous devices
- Latency: reduced by 75%
- Efficiency: 40% better battery life
- Security: WPA3 built in
Planning a business network:
Requirements analysis:
-
Device inventory
- Laptops and phones: 25 Mbps per device
- IoT devices: 1–5 Mbps per device
- Video conferencing: 50 Mbps per room
- Servers: 1 Gbps minimum
-
Coverage mapping
- Site survey with professional tools
- Identification of high-density areas
- Interference analysis
- AP planning per zone
-
Total bandwidth
- Rule of thumb: 20–30 Mbps per active user
- Concurrency factor: 60–80%
- Future growth: +25% a year
- Redundancy: double the critical bandwidth
Recommended network architecture:
Small company (1–20 employees):
Internet (100/100 Mbps)
↓
Business router/firewall
↓
24-port managed switch
↓
2–3 Wi-Fi 6 access points
Medium company (21–100 employees):
Internet (500/500 Mbps + backup)
↓
Business firewall + UTM
↓
Core switch (Layer 3)
↓ ↓ ↓
Access switches per floor
↓
5–10 Wi-Fi 6 access points
Large company (100+ employees):
Dual internet (1 Gbps + backup)
↓
Firewall cluster + load balancer
↓
Redundant core switch
↓ ↓ ↓
Distribution switches
↓ ↓ ↓
Access switches + PoE++
↓
10–50+ Wi-Fi 6E access points
Recommended equipment by budget:
Low budget (€2,000–5,000):
- Router: Ubiquiti Dream Machine Pro
- Switch: Netgear GS724T
- APs: Ubiquiti U6-Lite
- Cabling: basic Cat6
Mid budget (€5,000–15,000):
- Firewall: SonicWall TZ670
- Switch: Cisco CBS350 series
- APs: Cisco Meraki MR36
- Cabling: certified Cat6A
High budget (€15,000+):
- Firewall: Fortinet FortiGate
- Switch: Cisco Catalyst 9300
- APs: Aruba 630 series
- Cabling: Cat6A + fibre optic
Business VLAN configuration:
VLAN 10 — Management
- Network equipment and servers
- IT technical access only
- Maximum security
VLAN 20 — Employees
- Laptops and corporate devices
- Access to internal resources
- Filtered web browsing
VLAN 30 — Guests
- Temporary access without credentials
- Internet only, no internal network
- Limited bandwidth
VLAN 40 — IoT
- Smart devices
- Printers, cameras, sensors
- Restricted access
VLAN 50 — VoIP
- IP phones
- Priority QoS
- Minimum latency
Advanced network security:
1. 802.1X authentication
- Individual credentials per device
- Digital certificates
- A RADIUS server for authentication
2. Network Access Control (NAC)
- Device compliance checks
- Automatic quarantine of threats
- Granular policies per user
3. Monitoring and detection
- SIEM for log analysis
- Real-time IDS/IPS
- Anomalous behaviour analysis
Business Quality of Service (QoS):
Priority 1 (critical):
- VoIP: 64 kbps guaranteed
- Video conferencing: up to 50% of bandwidth
- Business-critical applications
Priority 2 (high):
- Corporate email
- ERP/CRM systems
- Business file transfers
Priority 3 (normal):
- General web browsing
- Productivity applications
- Software updates
Priority 4 (low):
- Personal streaming
- Social media
- Non-critical downloads
Monitoring and maintenance:
Essential tools:
- PRTG Network Monitor: all-round monitoring
- SolarWinds NPM: performance analysis
- Nagios: proactive alerting
- Wireshark: traffic analysis
Key metrics to monitor:
- Bandwidth utilisation per VLAN
- Average latency per segment
- Packet loss on critical links
- Device temperature and CPU
- Connected devices per AP
Maintenance plan:
Daily:
- Check automatic alerts
- Review security logs
- Monitor utilisation
Weekly:
- Back up configurations
- Review performance reports
- Check for offline devices
Monthly:
- Firmware updates
- Audit of users and permissions
- Capacity analysis
Quarterly:
- Coverage site survey
- Review of security policies
- Capacity planning
Common troubleshooting:
Speed problems:
- Check Wi-Fi channel utilisation
- Analyse RF interference
- Review the QoS configuration
- Check for duplex mismatch on switches
Connectivity problems:
- Check the DHCP scope
- Review the VLAN configuration
- Analyse authentication logs
- Check spanning tree
Migrating to Wi-Fi 6:
Phase 1 (month 1): planning
- Detailed site survey
- Design of the new topology
- Equipment selection
- Planning the maintenance windows
Phase 2 (month 2): gradual rollout
- Upgrade of the cabled infrastructure
- Installation of new APs zone by zone
- Configuration and testing
- Gradual migration of users
Phase 3 (month 3): optimisation
- Fine-tuning the configuration
- Performance analysis
- User training
- Complete documentation
Expected ROI:
- Productivity: +15% from better connectivity
- IT support: −30% network incidents
- Scalability: +200% supported devices
- Security: −80% network-related incidents
Implementation checklist:
✅ Professional site survey completed ✅ Network design validated by experts ✅ Business-grade equipment selected ✅ VLANs and security configured ✅ QoS implemented according to priorities ✅ Monitoring and alerting active ✅ Complete documentation available ✅ IT team trained on the new systems ✅ Backup and disaster recovery plan ✅ Maintenance procedures established