A logical network diagram shows how traffic is organized: VLANs, subnets, address ranges and the routing and firewall boundaries between them. A physical network diagram shows what is installed and where: devices, racks, ports and cables.
Reachability questions need the logical one; tracing a fault needs the physical one. CIS Controls v8 Safeguard 12.4 asks for architecture diagrams or other network documentation reviewed annually, and its assessment scores a review older than twelve months as a failure.
- A logical network diagram shows VLANs, subnets, routing and security boundaries
- A physical network diagram shows devices, locations, ports and cables
- Reachability needs the logical one; fault tracing needs the physical one
- CIS Safeguard 12.4 asks for architecture diagrams reviewed at least annually
- A diagram whose last review is over twelve months old fails that assessment
On this page
LogicalWhat a logical network diagram shows
A logical network diagram is a map of how the network is divided and how data is allowed to flow, created without regard to where any physical components sit.
Segments are the main objects. Each VLAN or subnet is a box with its name, its purpose and its address range: users, voice, servers, guest wireless, management. A reader should be able to see at a glance which subnet a device belongs to and what else shares it.
Boundaries are drawn as boundaries. The firewall or the routers that sit between two segments are the most important information on the diagram, because every access question is a question about crossing them. The VLANs are only half of the picture; the other half is where traffic between them is routed and filtered, which is the point of inter-VLAN routing.
Services appear as destinations, not boxes of hardware. The file server, the domain controllers, the internet edge, the VPN and the cloud connections are drawn where they sit logically, so that a question like "can the guest network reach the printers" has an answer on the page.
Detail is summarized. A logical network diagram with every workstation on it is unreadable, and network diagrams of that kind stop being used. The same advice applies as for drawing network nodes generally: draw the devices that carry and filter traffic, and summarize the endpoints as a count inside their segment.
Layer 2 and layer 3 logical diagrams
A logical network diagram can be drawn at two layers, and larger networks keep both types. A layer 3 diagram is a map of subnets, routers, firewalls and routing protocols, and shows how IP traffic gets from one segment to another. A layer 2 diagram shows VLANs, trunks and spanning tree, and which switches are connected in each broadcast domain.
The logical topology is often different from the physical topology. Devices wired in a physical star around one switch can sit in three separate VLANs, and two sites connected by a provider circuit can appear as one logical segment. A network topology diagram should say which of the two it is showing.
How to draw itHow to create a logical network diagram
The five steps below work in any drawing tool. Most tools ship network diagram templates and the standard symbols for routers, switches and firewalls, and the templates matter less than the information you collect before you create anything.
1. Collect the information. Export the VLAN list, the subnets and address ranges, the routing table of the core device, and the firewall zones. This is the content of the diagram. 2. Place the layer 3 devices first.
Routers, firewalls and layer 3 switches go in the middle, with the internet edge at the top. 3. Draw each subnet as one object connected to its gateway. Label it with the VLAN ID, name, address range and gateway address.
4. Add the services and external connections. Servers, cloud networks, VPN tunnels and provider circuits, each connected to the segment it lives in. 5. Mark what may cross each boundary, then add a title, a date, an owner and a legend.
A logical network diagram created this way for a small office fits on one page. When it stops fitting, split it by site or by layer, not by shrinking the text.
PhysicalWhat a physical network diagram shows
A physical network diagram is a picture of the physical components that are installed and where, created so that someone standing in the building can find them.
Devices by location. Buildings, floors, rooms and racks, with each switch, firewall, access point and server placed where it actually is.
Ports and cables. Which switch port connects to which patch panel position, which uplink runs to which closet, and what kind of link it is: copper, fiber, a wireless bridge, a provider circuit.
Rack elevations where they help. A drawing of each rack, top to bottom, with every device in its rack unit, answers most "where is it" questions faster than any list.
The physical diagram does not explain reachability. Two ports next to each other on the same switch can be in different VLANs with a firewall between them. Nothing on a physical network diagram shows that, which is exactly why the logical one exists.
Why twoWhy one diagram cannot do both jobs
The logical vs physical network diagram question is usually asked as which one to draw. For the reasons below, the answer is both.
They change for different reasons. The logical design changes when addressing, segmentation or security policy changes. The physical layout changes when hardware is added, moved or recabled. A single diagram that tracks both is out of date twice as often.
They serve different people. A security reviewer, an auditor or a network designer needs the logical view. A technician replacing a failed switch or tracing a cable needs the physical one. Putting both network diagrams on one page makes each of them worse.
They get too dense together. Overlaying VLAN colors, address ranges, port numbers and rack positions on the same diagram produces network diagrams that nobody can read at the size they will actually be printed or viewed.
Links between them are what matter. The practical arrangement is two diagrams with shared names: the switch called CORE-01 on the logical network diagram is the same CORE-01 in rack B2 on the physical one. The name is the key that lets someone move from one question to the other.
FrameworksWhat the security frameworks ask for
Diagrams stop being optional the moment a compliance framework is in play, and the CIS requirement is specific about both the document and its age.
CIS Controls v8, Safeguard 12.4. Often searched as CIS Control 12.4, it is the safeguard that turns a network architecture diagram into required network documentation.
Under Control 12, Network Infrastructure Management, Safeguard 12.4 reads: establish and maintain architecture diagram(s) and/or other network system documentation, and review and update the documentation annually, or when significant enterprise changes occur that could impact the safeguard. It sits in Implementation Groups 2 and 3, with the asset class Documentation and the security function Govern.
Stale counts as missing. The CIS assessment specification measures the safeguard in two steps. If the network architecture documentation does not exist, the safeguard is measured at 0 and fails.
If the time since its last review or update is greater than twelve months, it is also measured at 0 and fails. A diagram that exists but was last touched two years ago scores the same as no diagram.
The logical view is what these reviews need. A framework asking for architecture documentation is asking where the boundaries are, what data they protect, and how that data flows, which is the logical network diagram's job.
The subnet page makes the same point from the other side: segmentation is only enforceable, and only auditable, when the address ranges and the rules between them are written down.
Keeping them currentKeeping both network diagrams current
Put a date and an owner on each diagram you create. A diagram with no last-reviewed date cannot demonstrate the annual review a framework asks for, and one with no owner never gets reviewed.
Update on change, review on schedule. Make the diagrams part of the change process and the network plan for anything that alters addressing, segmentation or cabling, and review both diagrams at least once a year regardless, which is the cycle CIS Safeguard 12.4 sets.
Generate what can be generated. Network mapping and discovery software that reads switch neighbor tables and interface data can create much of a physical diagram and catch what humans forget. The logical design still needs a person, because intent, such as which segment is supposed to reach which, is not something a scan can see.
Keep the source, not just the image. Store the editable file next to the exported picture, in the same place as the rest of the configuration records, ideally linked from the configuration management database. A PDF nobody can edit becomes stale the first time something changes.
Make it usable at the worst moment. The diagram is needed most when the network is down, so a copy has to be reachable without the network, as the network issue checklist also recommends.
PitfallsWhere people go wrong
Creating one diagram and calling it both. It ends up either missing the VLANs or missing the cables, and usually missing the date.
Drawing every device. Two hundred workstations on a logical network diagram hide the ten boundaries that matter. Summarize endpoints inside their segment.
Leaving out the firewall rules' shape. A logical diagram with segments and no indication of what may cross between them answers the easy question and skips the one people actually ask.
No names shared between the two diagrams. Without a common device name, moving from "this traffic crosses FW-01" to "FW-01 is in rack A3, port 12" is guesswork.
Treating the diagram as a project with an end. The network changes every month. A diagram without a review date is already out of date, and under CIS Safeguard 12.4 a review more than twelve months old is scored as a failure.
Diagramming the intended network instead of the real one. The diagram from the network planning phase shows what was planned. The one an incident needs shows what is there, including the unmanaged switch under someone's desk.
ComparisonWhat each drawing shows, and what it cannot
| Criterion | Logical network diagram | Physical network diagram |
|---|---|---|
| Main objects | VLANs, subnets, security zones | Devices, racks, rooms |
| Shows address ranges | Yes | No |
| Shows ports and cables | No | Yes |
| Shows where traffic is filtered | Yes | No |
| Shows where a device is installed | No | Yes |
| Changes with | Addressing and policy | Hardware and cabling |
| Needed for a security review | Yes | Supporting |
| Needed to replace a failed switch | Supporting | Yes |
The rows that each of the two network diagrams lacks are the argument for keeping both.
FAQFrequently asked questions
What is a logical network diagram?
A diagram of how a network is divided and how data may flow: the VLANs and subnets with their address ranges, and the routers and firewalls between them. It deliberately ignores where devices are physically installed.
What is a physical network diagram?
A diagram of the physical components that are installed and where: devices by building, room and rack, with the ports and cables that connect them. It shows how to find things, not how traffic is allowed to flow.
What is the difference between a logical and a physical network diagram?
The logical network diagram answers "what can reach what, and through which boundary". The physical diagram answers "where is it, and which cable connects it". Most real questions need one or the other, rarely both at once.
Do I need both?
For anything beyond a very small office, yes. The two network diagrams change for different reasons and serve different people, and a single combined diagram tends to become unreadable and out of date.
What should a logical network diagram include?
Each segment with its name, purpose and address range, the devices that route and filter between segments, the key services such as domain controllers and file servers, the internet edge and remote access, and a count of endpoints per segment rather than every endpoint.
What should a physical network diagram include?
Locations, racks, every network device with its name, port-to-port connections including patch panel positions, uplinks between closets, and the type of each link.
Does a compliance framework require a network diagram?
CIS Controls v8 Safeguard 12.4 requires organizations in Implementation Groups 2 and 3 to establish and maintain architecture diagrams or other network system documentation, reviewed annually or after significant change.
How often should network diagrams be updated?
On every change that affects addressing, segmentation or cabling, and reviewed at least annually. The CIS assessment specification fails the safeguard when the last review is more than twelve months old.
Can a tool generate a network diagram automatically?
Discovery software can create much of the physical layout from the information devices report about their neighbors and interfaces. The logical design, especially which segments are meant to reach which, still has to be drawn by someone who knows the intent.
Which diagram does an auditor want?
Usually the logical one, because an audit asks where the security boundaries are and what they protect. The physical diagram supports it by showing that the boundaries exist in real equipment.
What is a network topology diagram?
A diagram of the shape of the connections, such as star, bus or mesh. It can be drawn logically or physically, which is why the two terms get used interchangeably and why it helps to say which one you mean.
Where should network diagrams be stored?
With the rest of the configuration records, as editable source files alongside exported images, with a copy reachable when the network itself is down.
Keep readingRelated concepts
Read next · Addressing What Is a Subnet? The address ranges that label each segment on the logical drawing. Open this next15 min- Switching · 14 min What Is a VLAN? The segments a logical network diagram is mostly made of.
- Cabling · 13 min What Is a Patch Panel, and Why It Does Nothing At All The port positions a physical network diagram records for every run.