WHITE PAPER
Page 3
White Paper 
Network Segmentation on NETGEAR Orbi Pro WiFi 6 Series
Abstract
NETGEAR Orbi Pro WiFi 6 Series makes it simple and fast for small and medium businesses (SMBs) to achieve 
network security by easily creating multiple and distinct IP Layer3 local area networks (LANs). Benets include 
having separate LANs for different users with different proles, such as one for guests who want to access the 
Internet, and another for transferring condential company information. 
With Network Segmentation, separate LANs can be created on an IP level across both WiFi and Ethernet ports. 
With Orbi Pro’s unique wireless backhaul technology Network segmentation can be implemented across 
locations where it is difcult or impossible to run extra cables. 
Network Segmentation is just one of the outstanding features of NETGEAR Orbi Pro WiFi 6 wireless mesh 
system, with others including: unparalleled coverage, extensive capacity, high and reliable performance, and its 
existing security strengths. 
This white paper focuses on Network Segmentation, and explores how Orbi Pro brings enterprise level 
security features to small and medium sized businesses (SMBs). It also includes a guide to setting up Network 
Segmentation with Orbi Pro WiFi6 SXK80 and Orbi Pro WiFi 6 Mini SXK30.
Key Terms
  LAN – Local Area Network (LAN) is a network that provides network connectivity for a group of devices at one 
physical location, such as an ofce, another type of work building, or at home
  IP Segmentation – Creates multiple Layer 3 IP networks
  Virtual Local Area Network (VLAN) – Creates separate sub-networks on the same Layer 3 network 
  IP (Internet Protocol) Address – A numerical label, such as 192.0.2.1, that is connected to a computer network 
that uses the Internet Protocol for communication. An IP address serves two main functions: host or network 
interface identication and location addressing.
  Client Isolation – Orbi Pro provides the ability to isolate clients on the same VLAN 
  Network Isolation – Orbi Pro provides the ability to isolate hosts, ports and different clients in the VLAN, 
thereby increasing security
 VLANProles – Specication of the VLAN prole to apply to each port or wireless SSID 
  Access Mode – Allows the direct connection to only client or end devices
  Trunk Mode – Enables forwarding of tagged packets with a specic VLAN tag only.
What is Network Segmentation?
Ideally, many SMBs want to create separate and secure networks for their information assets.). Each LAN or VLAN 
is dedicated to a particular purpose, for example, a guest network isolated from internal VLANs, with all its wired/
wireless trafc is directed through the Internet. 








