Secure Integration of IoT Devices into Enterprise NetworksUsing VLAN Segmentation and Access Control Policies
Abstract
The explosion in number of IoT devices in enterprise network has presented an interesting security problem. The smart cameras, environment monitors, printers, access control units, building controllers, and other devices are commonly placed near corporate devices but are generally less protected by more vulnerable firmware, less monitored and have different patch schedules. This paper provides a secure integration framework for IoT devices based on VLAN segmentation and access control policies. This framework, referred to here as SIVAC-IoT, classifies devices into role-based VLANs, assigns least-privilege access policy to each VLAN, and controls communications between VLANs using Layer-3 ACLs, firewall policies, and logging controls. The paper presents a structured enterprise-network implementation framework supported by clear topology design, policy engineering, validation procedures, and measurable security outcomes suitable for professional deployment planning. The evaluation criteria include the reduction of lateral movement, prevention of unauthorized flows, broadcast-domain control, policy overhead, and maintainability. The experimental results show that moving from a traditional flat enterprise design to a VLAN-based architecture with clearly defined access control significantly reduces unnecessary connectivity between IoT devices and corporate resources while maintaining a modest latency overhead. Most importantly, secure integration of IoT into enterprise networks requires intentional design rather than simply connecting devices to switch ports.