Network Design LAN WAN Topology Diagram
A LAN WAN topology diagram shows how local networks at different sites connect over wide area links to form a unified corporate network. It's essential for network planning and troubleshooting across multiple locations. Tip: clearly mark bandwidth and link type on each WAN connection for capacity planning.
The prompt behind this diagram
Create a network design diagram showing a headquarters LAN with a core switch connected to a distribution switch, which connects to access switches serving workstations in Sales, Engineering, and Support departments. Connect the headquarters to a branch office LAN via a WAN link through routers at each site, and include a firewall at the WAN edge of each location plus a VPN tunnel between the two sites for secure communication.
Paste your own description (or Terraform / docker-compose / SQL schema) into draft1 and get a diagram like this for your exact system.
What this diagram shows
This diagram illustrates the physical and logical layout of a hybrid local and wide area network. It depicts how branch office LANs connect to a central headquarters network through WAN links, managed by routers and secured by firewalls. The flow shows data moving from end devices (workstations, servers) through access switches at the edge, aggregating to core switches, passing through firewalls for security inspection, routing across WAN connections (leased lines, MPLS, Internet), and reaching remote sites. VPN tunnels provide encrypted paths for secure communication. The topology shows redundancy points, trust boundaries, and the hierarchical aggregation of traffic from access to distribution to core layers.
Key components
- Access Switches — Connect end devices such as workstations, printers, and VoIP phones directly to the LAN at the branch or campus level.
- Core Switches — Aggregate traffic from multiple access switches and distribution layers, handling the highest throughput at the network centre.
- Firewalls — Inspect and filter traffic between trusted internal networks and untrusted external networks, enforcing security policies.
- Routers — Forward packets between different subnets and WAN links, managing routing tables and determining optimal paths.
- WAN Links — Carry traffic between geographically separated sites using technologies such as MPLS, leased lines, or broadband connections.
- VPN Concentrator or Gateway — Terminates encrypted VPN tunnels for secure remote access and site-to-site connectivity over public networks.
- Servers — Host applications, file storage, and services accessible to users across both LAN and WAN segments.
When to use it
Use this diagram when designing or documenting an enterprise network spanning multiple locations or departments. It suits scenarios where you need to show the relationship between local and remote connectivity, security enforcement points, and traffic flow paths. This is essential for network architects planning upgrades, documenting existing infrastructure for compliance audits, or communicating topology to stakeholders. It works well for medium to large organisations with branch offices, data centres, and remote workers connecting over WAN.
Common mistakes
- Omitting firewall boundaries or assuming all internal traffic is trusted, which can allow lateral movement of threats across the network.
- Failing to show redundancy in critical links such as WAN connections, leaving no failover path if the primary route fails.
- Placing VPN termination outside the firewall or mixing it with the core switching fabric, which complicates security policy enforcement and creates configuration ambiguity.
Adapting it to your system
Start by identifying your actual network layers: access tier (what devices connect directly?), distribution tier (what aggregates their traffic?), and core tier (what moves traffic between sites?). List your physical locations and the WAN technologies linking them (MPLS, Internet, leased lines). Add your firewall locations at trust boundaries, typically between the core and WAN. Include your specific routing devices, VPN endpoints, and security appliances. Show VLAN segmentation if relevant, and mark redundant links with multiple lines or dotted alternates. Adjust the diagram to match your site count, link speeds, and whether you use a hub-and-spoke or mesh topology.
More templates
System Architecture Diagram
Generate a clear system architecture diagram online and export an editable draw.io file in seconds with AI.
Network Topology Diagram
Draw a network topology diagram instantly with AI and download it as an editable draw.io file for your documentation.
Aktivitätsdiagramm Für Eine Java-Methode Erstellen
Erstellen Sie ein UML-Aktivitätsdiagramm für Java-Methoden mit KI und exportieren Sie es als editierbare draw.io-Datei
Diagram Przypadków Użycia UML
Wygeneruj diagram przypadków użycia UML online za pomocą AI i pobierz edytowalny plik draw.io.
Cloud Architecture Diagram
Create a cloud architecture diagram with AI and export it instantly as an editable draw.io file.
Cloud Infrastructure Diagram
Generate a detailed cloud infrastructure diagram online using AI and export it as an editable draw.io diagram.
Business Process Flowchart With Decision Points
Build a business process flowchart with decision points using AI and download an editable draw.io file.