In Firewall basics, you saw a firewall separate the inside network from the internet and the DMZ. But what about the inside network itself? In many small offices, every device, from the manager's laptop to the coffee machine, sits in one large network where any device can talk to any other. Segmentation fixes that.
💡 In simple terms: a ship is built with watertight compartments. If the hull is damaged, one compartment floods, the doors close and the ship stays afloat. A segmented network works the same way: one compromised device affects one compartment, not the whole ship.
What network segmentation is
Network segmentation means dividing a network into smaller parts, called segments or zones, and then controlling the traffic between them with rules. It needs two things:
- Separation: devices are placed in different networks, so they can't reach each other directly.
- Control: a device in the middle (normally a firewall) decides which traffic may cross from one segment to another.
Separation without control is just tidiness. Control without separation is impossible, because the firewall can't check traffic that never passes through it. Segmentation needs both.
Why it matters: the flat network problem
A flat network is one big segment: one subnet, one broadcast domain and no internal rules. It is simple to build, and it works well until something malicious gets in.
Lateral movement
Attackers rarely break straight into the most valuable server. They first get a foothold somewhere easy, such as a laptop through a phishing email or a camera with a default password. Then they move sideways from device to device, looking for something valuable. This is called lateral movement. On a flat network, nothing stands in their way.
Blast radius
The blast radius is how much can be damaged when one thing goes wrong. For example, ransomware on one PC in a flat network can scan and encrypt every reachable file share. In a segmented network, it can only reach what that PC's segment is allowed to reach.
- 1. Without rules (a flat network), the malware reaches everything. Every server, camera and admin page answers its scan. One infection can turn into a company-wide outage.
- 2. With segmentation, staff can still use the file server… Rule: Staff → Servers, TCP 445 allowed. The malware can still reach the shares this user can reach, which is why backups still matter.
- 3. …but the IoT and management segments are closed. Staff → IoT and Staff → Management are denied and logged. The infection is contained, and the log entries alert the IT team.
Other benefits
- Least privilege for networks: each group can reach only what it needs, the same least-privilege principle used for user accounts.
- Visibility: traffic between segments passes through a firewall, which logs it, so unusual flows stand out.
- Smaller broadcast domains: each segment is its own broadcast domain, so broadcasts such as ARP and DHCP stay local.
- Compliance: security standards for card payments and health data expect sensitive systems to be separated from everything else.
- Containing faults: a misbehaving device, such as a rogue DHCP server or the cause of a broadcast storm, only affects its own segment.
Where segmentation happens
The key fact is this: traffic inside one subnet never passes through the firewall. Two PCs in 192.168.10.0/24 talk directly through the switch, using ARP to find each other's MAC address. A PC sends a packet to its default gateway only when the destination is in a different subnet. So the boundary between segments is the router or firewall that acts as the default gateway, and that is where the rules are applied.
This is the same different-subnet journey that a later lesson follows step by step, with the firewall acting as the router.
Learn more: Different-Subnet Communication
Ways to segment a network
Separate physical networks
Subnets
VLANs
Firewalls between zones
Guest networks
DMZ
Host firewalls and microsegmentation
Cloud segmentation
VLANs, conceptually
VLANs deserve a closer look because they are the most common segmentation tool. Without VLANs, five segments would need five sets of switches. With VLANs, one switch can carry all five: the administrator assigns each port to a VLAN, and the switch never forwards frames between VLANs. Each VLAN is its own broadcast domain. A link that carries several VLANs between switches (a trunk) tags each frame with its VLAN number, so the VLANs stay separate.
Remember: a VLAN separates devices, but it doesn't decide what may cross. If the device that routes between VLANs simply allows everything, you have several subnets but the security of one flat network. The rules on that routing device are what make segmentation a security control.
Going further (CCNA): how to create VLANs, assign ports and configure trunks on Cisco switches is covered in the CCNA lesson VLANs and trunks. You don't need it for this course.
Guest networks
Guest Wi-Fi is the simplest form of segmentation most people use. The access point broadcasts a second network name (SSID) that is mapped to its own segment, 192.168.50.0/24, with its own DHCP range. The firewall allows guests to reach the internet and denies everything towards internal subnets. Good guest networks also turn on client isolation, so guests can't reach each other either.
Learn more: Wireless Security
The DMZ
A DMZ (demilitarised zone) is a segment for systems that must accept connections from the internet: a public website, a mail gateway, a VPN portal. Because they are exposed, they are the most likely to be attacked, so they are kept out of the internal network. A typical rule set says:
- The internet may reach the DMZ on a few ports only.
- The DMZ may reach the inside only on very specific ports, for example from the web server to the database.
- The inside network may manage the DMZ.
Example: segmenting a small office
Here is a 60-person office that has been redesigned from one flat network into seven segments. The firewall is the default gateway (.1) in every segment.
| Segment | Subnet | Who lives there | Trust |
|---|---|---|---|
| Staff | 192.168.10.0/24 | Staff laptops and desktops | Medium |
| Servers | 192.168.30.0/24 | File server, database, intranet | High |
| Printers & IoT | 192.168.40.0/24 | Printers, cameras, door controllers, smart TVs | Low |
| Guest Wi-Fi | 192.168.50.0/24 | Visitors' phones and laptops | None |
| Management | 192.168.99.0/24 | Admin interfaces of switches, access points, firewall | Highest |
| VPN users | 10.8.0.0/24 | Remote staff connected through the VPN | Medium |
| DMZ | 172.16.1.0/24 | Public web server | Low (exposed to the internet) |
Next come the allowed flows. Anything not listed is blocked by the implicit deny at the end of the rule list.
| From | To | Service | Decision |
|---|---|---|---|
| Staff | Internet | Web (TCP 80, 443), DNS | ✅ Allow |
| Staff | Servers | File sharing (TCP 445), intranet (TCP 443) | ✅ Allow |
| Staff | Printers & IoT | Printing only (TCP 9100, 631) | ✅ Allow |
| VPN users | Servers | File sharing and intranet only | ✅ Allow |
| Guest Wi-Fi | Internet | Web and DNS | ✅ Allow |
| Guest Wi-Fi | Any internal segment | Anything | ❌ Deny (and log) |
| Printers & IoT | Staff or Servers | Anything | ❌ Deny (and log) |
| Internet | DMZ | HTTPS (TCP 443) to the web server | ✅ Allow |
| DMZ | Servers | Only the web server to the database port | ✅ Allow |
| Internet | Any internal segment | Anything | ❌ Deny (and log) |
| IT admin PCs | Management | SSH, HTTPS | ✅ Allow |
| Everyone else | Management | Anything | ❌ Deny (and log) |
- 1. Staff → Servers, file sharing: allowed. The laptop sends the packet to its default gateway. The firewall matches the Staff → Servers rule and routes it.
- 2. Staff → Printers, printing: allowed. Only the printing ports are open, so staff can't reach the printer's admin page.
- 3. Guest → Internet: allowed. Visitors get internet access, which is all they need.
- 4. Guest → Servers: denied. The guest network can't reach anything internal. The attempt is logged.
- 5. Printer → Staff: denied. If the printer is ever compromised, it can't be used to attack staff laptops.
- 6. Internet → DMZ web server: allowed. The only way in from the internet leads to the DMZ, not to the internal network.
Designing your own segments
- List the groups of devices and people: staff, servers, guests, IoT devices and admin interfaces.
- Rank their trust. Anything you can't patch or control, such as IoT devices and guests, gets low trust.
- Write down the flows each group really needs. Ask the application owners which ports their applications use.
- Give each segment its own subnet (and usually its own VLAN and DHCP scope). The Subnet Calculator helps you plan the ranges.
- Make the firewall the default gateway for each segment, allow only the listed flows, and log everything that is denied.
- Watch the logs for a few weeks. Add rules for genuine needs you missed, and question everything else.
What happens when segmentation goes wrong
| Problem | Result |
|---|---|
| “Allow any → any” between internal segments | Many subnets, but the security of a flat network |
| A device plugged into a port in the wrong segment | It gets an address in the wrong subnet from DHCP, so it either can't work or can reach things it shouldn't |
| Guest Wi-Fi mapped to the staff segment by mistake | Visitors can reach internal servers |
| An application flow forgotten in the design | The application breaks after the change; users see timeouts |
| Management interfaces reachable from every segment | An attacker on any PC can try to log in to the switches and firewall |
| The firewall between segments fails | All traffic between segments stops; traffic inside each segment keeps working |
Troubleshooting and useful commands
Start by checking which segment a device is actually in:
C:\> ipconfig Ethernet adapter Ethernet: Connection-specific DNS Suffix . : office.example IPv4 Address. . . . . . . . . . . : 192.168.10.23 Subnet Mask . . . . . . . . . . . : 255.255.255.0 Default Gateway . . . . . . . . . : 192.168.10.1
What to look for: IPv4 Address 192.168.10.23 with a 255.255.255.0 (/24) Subnet Mask and Default Gateway 192.168.10.1 means this PC is in the Staff segment. If a staff PC shows a 192.168.50.x address, it is plugged into a guest port or has joined the guest Wi-Fi.
Then check whether traffic crosses the firewall, and where it stops. The -d option skips name lookups, so the output shows only IP addresses:
C:\> tracert -d 192.168.30.10 Tracing route to 192.168.30.10 over a maximum of 30 hops 1 2 ms 1 ms 1 ms 192.168.50.1 2 * * * Request timed out. 3 * * * Request timed out. 4 * * * Request timed out. ^C
What to look for: hop 1, 192.168.50.1, is the firewall's guest interface. After that, every hop shows Request timed out: the firewall silently drops guest traffic to the server segment, as designed. From a staff PC, the same command would show 192.168.10.1 as hop 1 and the server itself as hop 2.
Finally, test the exact service a user needs:
PS C:\> Test-NetConnection 192.168.30.10 -Port 445 ComputerName : 192.168.30.10 RemoteAddress : 192.168.30.10 RemotePort : 445 InterfaceAlias : Ethernet SourceAddress : 192.168.10.23 TcpTestSucceeded : True
What to look for: TcpTestSucceeded : True means the Staff → Servers file-sharing flow works. SourceAddress confirms the test came from the Staff subnet. If the result were False, check the firewall log for a deny between those two subnets, then check the host firewall on the server.
Common mistakes
- Creating VLANs and then allowing everything between them. This gives separation without control, so an attacker can still move freely between segments.
- Putting IoT devices in the staff segment. Cameras and printers are often old and unpatched, so they belong in a low-trust segment.
- Forgetting the management network. The admin pages of switches, access points and the firewall should be reachable only from IT admin PCs.
- Creating too many tiny segments at once. Start with a few clear zones; complex designs lead to mistakes.
- Treating VPN users as fully trusted. Give VPN users their own segment and only the access they need.
- Not logging denied flows. The logs are how you notice both a missing rule and an attacker.
- Segmentation splits a network into zones and controls the traffic between them.
- It limits the blast radius of an incident and makes lateral movement harder.
- Traffic inside one subnet never passes through the firewall, so segments must be separate subnets for its rules to apply.
- Common tools: subnets, VLANs, firewalls between zones, guest networks, a DMZ and host firewalls.
- A VLAN separates devices; the firewall rules between VLANs provide the security.
- To design segments, list the groups, rank their trust, allow only the flows they need and log the rest.
Knowledge check
Two PCs are both in 192.168.10.0/24. A firewall rule says 'deny Staff → Staff'. Can the firewall stop them communicating?
An office puts staff in VLAN 10 and printers in VLAN 40 on separate subnets, but the firewall between them allows any → any. A hacked printer scans staff laptops. What happens?
Ransomware infects a laptop on guest Wi-Fi. The guest segment may only reach the internet. Which is most likely protected?
A company is launching a public website on its own server, which must accept connections from the internet. Which segment should the server go in?
Where to go next
You now know the four pillars of network security covered in this course: the principles in Basic network security, the rules in Firewall basics, protected paths with VPN basics, and the zones in this lesson. Next, the course puts everything together and follows packets end to end, starting with Same-subnet communication.