Network segmentation means logically or physically separating the different zones of an information system. It's a fundamental principle of both security and architecture.
Why segment?
- Limit propagation: a local compromise stays contained
- Control traffic: only necessary exchanges are allowed
- Improve visibility: the infrastructure becomes easier to read
- Ease administration: better separation of usages
Example segments
- User workstations
- Internal servers
- Guest Wi-Fi
- Administration
- DMZ for exposed services
The role of VLANs and ACLs
VLANs isolate broadcast domains, while ACLs and firewalls control communication between segments.
A logical approach
Segmentation should be designed around business needs, application flows, and the sensitivity level of resources.
A good network isn't one where everything talks to everything. It's one where every flow has a justification.