Addressing, VLANs and
segmentation — finally in
one place.

Every prefix, VLAN and VRF across production and enterprise, with live utilization and
a reconcile pass that shows you where the spreadsheet and the network disagree.
Writes go through approval, so the record stays trustworthy.

⁂IPAM 14 prefixes 43 declared DEMO PLAN writes go through the approval workflow
VRF
⌕
No prefixes match.
VLANs
VRFs prod · staging · oob · dmz · dr
RECONCILIATION
43 declared. 14 actually there.
Every IPAM eventually drifts from reality — someone allocates a subnet in a hurry, a
migration stalls, a lab range never gets returned. Reconcile compares what’s declared
against what discovery actually finds on the network.
DECLARED · source of record43
prefixes in the plan43
VLANs declared14
VRFs defined5
last manual edit11 months ago
29
DRIFT
reconcile pass
DISCOVERED · on the network14
prefixes carrying traffic14
VLANs seen on switches14
unmanaged range found1
last syncjust now
⚠
29 declared prefixes carry no traffic
Allocated in the plan but never seen on any switch or router. Likely reclaimable — 7,394 addresses sitting idle.

Review & reclaim

✦
Unmanaged range in use: 10.40.9.0/24
Legacy voice segment carrying live traffic with a migration marked pending since last year. Not in any current VRF plan.

Adopt into prod

⇄
VLAN 409 outside its numbering scheme
Every other prod VLAN sits in 110–130. This one breaks the convention, which is usually the fingerprint of an emergency allocation.

Flag for renumber

✓
No overlapping subnets detected
All 14 live prefixes are non-overlapping across the five VRFs. Segmentation boundaries hold.

Clean

Nothing is changed by a reconcile pass — writes go through the approval workflow, so the record only moves when a human says so.
NETWORK SEGMENTATION & VRF VISIBILITY

Five VRFs, and what lives in each.

Segmentation only means something if you can see it. Every prefix and VLAN grouped
by the routing domain it belongs to.
prod
Production
110 core network
111 edge / LB
112 GPU fabric
113 kubernetes
114 cache / message
120 database tier
121 db replicas
130 compute pool
409 legacy voice
9 prefixes · 2,286 addresses
staging
Pre-production
980 compute pool
990 shared services
2 prefixes · 508 addresses
oob
Out-of-band
500 management
1 prefix · isolated from prod
dmz
Partner edge
600 DMZ / partner ingress
1 prefix · externally reachable
dr
Disaster recovery
700 warm standby (eastus2)
1 prefix · cross-region
UTILIZATION TRACKING
You’re using 1% of what you reserved.
Most estates allocate /24s out of habit and use a handful of addresses. That’s not harmful until you run out of blocks to hand out — then it’s a migration.

1

Per-prefix utilization
Live used-versus-available on every range, not a number someone typed in 2023.

2

Right-sizing candidates
A /24 holding 3 hosts is a /29’s worth of work occupying 254 addresses.

3

Exhaustion forecast
Growth trend per VRF, so you widen a range before an allocation fails.

4

Reclamation queue
Idle ranges surfaced for return, with evidence they carry no traffic.
UTILIZATION BY VRF3,556 of 3,556 reserved
prod31 / 2,286 · 1.4%
staging4 / 508 · 0.8%
oob3 / 254 · 1.2%
dmz3 / 254 · 1.2%
dr3 / 254 · 1.2%
7,394 addressesreclaimable across 29 declared-but-idle prefixes
CAPABILITIES
What the IPAM view covers.
⁂
IP prefix management
Every CIDR block with its purpose, VLAN, VRF and live occupancy.
▦
VLAN visibility
All VLAN IDs and their named purpose, matched to the prefixes they carry.
⇉
VRF visibility
prod, staging, oob, dmz and dr as first-class routing domains you can filter by.
🛡
Network segmentation
See which ranges are isolated, externally reachable, or crossing regions.
📈
Utilization tracking
Live per-prefix and per-VRF usage, with right-sizing candidates surfaced.
⟳
Reconciliation
Declared plan versus discovered reality, with every difference itemised.
✓
Approval-gated writes
Nothing changes the record without going through the approval workflow.
⚠
Conflict detection
Overlapping subnets, off-scheme VLANs and unmanaged ranges flagged.
🔗
Estate-linked
Each prefix ties back to the hosts, switches and services actually inside it.
WHY IT MATTERS
The spreadsheet nobody trusts,
retired.
Addressing is where a small documentation gap becomes an outage — a duplicate
allocation, a VLAN that shouldn’t route where it does, a range everyone assumed was free.
SOURCE OF TRUTH
a stale spreadsheet
reconciled daily
Declared plan checked against what discovery finds.
RECLAIMABLE SPACE
unknown
7,394 addresses
Idle ranges identified with evidence, not guesswork.
DUPLICATE ALLOCATION
found in production
blocked at request
Conflicts detected before the change goes out.
AUDIT EVIDENCE
reconstructed
already
there
Segmentation boundaries provable per VRF.
👤
For the network engineer
DAY TO DAY
✓
Allocate without fear
You can see what’s genuinely free instead of hoping the sheet is current.
✓
Find the orphans
Reconcile names the ranges nobody has touched in a year, with proof.
✓
Answer segmentation questions fast
“Can DMZ reach the database tier?” is a filter, not an afternoon of config reading.
✓
Your changes are reviewable
Approval-gated writes mean nobody quietly edits the
record.
◈
For the organization
ON THE BALANCE SHEET
✓
Defer the renumbering project
Reclaiming idle space is far cheaper than a migration to a bigger scheme.
✓
Fewer self-inflicted outages
Duplicate and overlapping allocations are a classic avoidable
cause.
✓
Segmentation you can evidence
Auditors ask you to prove isolation, not describe
it.
✓
Migration and DR readiness
You can’t move or fail over what you can’t accurately
describe.
Console figures are illustrative. Coverage depends on the discovery sources and sites you connect.
Get started
Run one reconcile pass
on your real network
Import your existing plan and we’ll show you exactly where it
disagrees with what’s on the wire.
Autonomous ITOps platform powered by an AI Coworker, SRE Orchestrator, and Agent Builder
© 2026 – 2027 LumiOps.AI. All rights reserved.

© 2026 – 2027 LumiOps.AI. All rights reserved.