Network segmentation means logically or physically separating the different zones of an information system. It's a fundamental principle of both security and architecture.

Why segment?

  • Limit propagation: a local compromise stays contained
  • Control traffic: only necessary exchanges are allowed
  • Improve visibility: the infrastructure becomes easier to read
  • Ease administration: better separation of usages

Example segments

  • User workstations
  • Internal servers
  • Guest Wi-Fi
  • Administration
  • DMZ for exposed services

The role of VLANs and ACLs

VLANs isolate broadcast domains, while ACLs and firewalls control communication between segments.

A logical approach

Segmentation should be designed around business needs, application flows, and the sensitivity level of resources.

A good network isn't one where everything talks to everything. It's one where every flow has a justification.