Segmentation goal: Create boundaries that remain useful during an incident. A VLAN alone is not sufficient if routing permits unrestricted access.
Typical boundaries
| Zone | Typical policy |
|---|---|
| Users | Permit only required server applications. |
| Servers | Restrict east-west access. |
| Management | Highly restricted administrative access. |
| Backups | Separate from ordinary production administration. |
| Critical systems | Strongest access controls and monitoring. |
Enforce the boundary
Use routing and firewall policy to control traffic between VLANs. Avoid broad internal any-to-any rules and review management interfaces separately from application traffic.
Use the VLAN Planner for addressing and the Firewall Policy Analyzer for exported policy review.
Containment
Define how a compromised user network can be isolated quickly without disconnecting the entire organisation. Document who can make the change and how it will be reversed.
Validate
Test representative permitted and denied flows. A segmentation design that is never tested may contain incorrect assumptions.