Routelearn.net
Course menu

Unit 12: Network Security FundamentalsLesson 12.4 (4 of 4 in this unit)69 of 84 in the Network Fundamentals course

Network Segmentation

Segmentation means splitting one network into smaller parts and controlling what may travel between them. When something goes wrong in one part, such as a virus on a laptop, the damage stays there. This lesson explains why that matters and the main ways to segment a network, then walks through a complete office design.

Beginner · 15 min read · Before this: Firewall basics, Subnet mask basics, The default gateway

Network segmentation is the practice of dividing a network into smaller segments, such as VLANs or subnets, and controlling which traffic may pass between them, so that faults and attacks in one segment stay contained.

In simple terms: Segmentation splits one big network into separate rooms with locked doors between them. If something goes wrong in one room, it doesn’t spread to the others.

In Firewall basics, you saw a firewall separate the inside network from the internet and the DMZ. But what about the inside network itself? In many small offices, every device, from the manager's laptop to the coffee machine, sits in one large network where any device can talk to any other. Segmentation fixes that.

💡 In simple terms: a ship is built with watertight compartments. If the hull is damaged, one compartment floods, the doors close and the ship stays afloat. A segmented network works the same way: one compromised device affects one compartment, not the whole ship.

What network segmentation is

Network segmentation means dividing a network into smaller parts, called segments or zones, and then controlling the traffic between them with rules. It needs two things:

  1. Separation: devices are placed in different networks, so they can't reach each other directly.
  2. Control: a device in the middle (normally a firewall) decides which traffic may cross from one segment to another.

Separation without control is just tidiness. Control without separation is impossible, because the firewall can't check traffic that never passes through it. Segmentation needs both.

Why it matters: the flat network problem

A flat network is one big segment: one subnet, one broadcast domain and no internal rules. It is simple to build, and it works well until something malicious gets in.

Lateral movement

Attackers rarely break straight into the most valuable server. They first get a foothold somewhere easy, such as a laptop through a phishing email or a camera with a default password. Then they move sideways from device to device, looking for something valuable. This is called lateral movement. On a flat network, nothing stands in their way.

Blast radius

The blast radius is how much can be damaged when one thing goes wrong. For example, ransomware on one PC in a flat network can scan and encrypt every reachable file share. In a segmented network, it can only reach what that PC's segment is allowed to reach.

staff segmentserversIoTmanagementmalwareInfected PCStaff 192.168.10.23Internal firewallFile server192.168.30.10Camera recorder192.168.40.15Switch admin page192.168.99.2
  1. 1. Without rules (a flat network), the malware reaches everything. Every server, camera and admin page answers its scan. One infection can turn into a company-wide outage.
  2. 2. With segmentation, staff can still use the file server… Rule: Staff → Servers, TCP 445 allowed. The malware can still reach the shares this user can reach, which is why backups still matter.
  3. 3. …but the IoT and management segments are closed. Staff → IoT and Staff → Management are denied and logged. The infection is contained, and the log entries alert the IT team.
Segmentation doesn't stop the first infection. It limits what that infection can reach next, and makes the attempt visible in the firewall logs.

Other benefits

  • Least privilege for networks: each group can reach only what it needs, the same least-privilege principle used for user accounts.
  • Visibility: traffic between segments passes through a firewall, which logs it, so unusual flows stand out.
  • Smaller broadcast domains: each segment is its own broadcast domain, so broadcasts such as ARP and DHCP stay local.
  • Compliance: security standards for card payments and health data expect sensitive systems to be separated from everything else.
  • Containing faults: a misbehaving device, such as a rogue DHCP server or the cause of a broadcast storm, only affects its own segment.

Where segmentation happens

The key fact is this: traffic inside one subnet never passes through the firewall. Two PCs in 192.168.10.0/24 talk directly through the switch, using ARP to find each other's MAC address. A PC sends a packet to its default gateway only when the destination is in a different subnet. So the boundary between segments is the router or firewall that acts as the default gateway, and that is where the rules are applied.

1. Staff PC 192.168.10.23 wants 192.168.30.10
Its subnet mask shows that the server is in a different subnet
2. Sends the packet to its default gateway
The frame goes to the firewall's MAC address; the IP header still says 192.168.10.23 → 192.168.30.10
3. The firewall checks its rules
Source zone Staff, destination zone Servers, service TCP 445
4. Allowed: routed into the server segment
A new frame carries the server's MAC address; the IP addresses are unchanged
5. Replies come back through the state table
A stateful firewall needs no separate rule for the return traffic
Crossing between segments is ordinary routing with a rule check in the middle. The firewall rewrites the MAC addresses in the new frame; the IP addresses stay the same.

This is the same different-subnet journey that a later lesson follows step by step, with the firewall acting as the router.

Learn more: Different-Subnet Communication

Ways to segment a network

Separate physical networks

Different switches and cables for each segment. Very clear and very strong separation, but expensive, and wasteful when a segment has only a few devices.

Subnets

Each segment gets its own IP address range, for example 192.168.10.0/24 for staff and 192.168.30.0/24 for servers. Separate subnets force traffic between groups through the gateway, where the firewall can filter it.

VLANs

A virtual LAN (VLAN) splits one switch into several separate LANs. Ports in VLAN 10 and VLAN 30 can't communicate at Layer 2, as if they were on different switches. Usually, one VLAN = one subnet = one segment.

Firewalls between zones

An internal firewall (or a Layer 3 switch with access rules) routes between the segments and enforces what may cross. This is where the security policy is applied.

Guest networks

A separate Wi-Fi network (SSID) for visitors. It is mapped to its own segment and allowed to reach the internet, but nothing else.

DMZ

A segment for servers that the public must reach. If one of them is broken into, the attacker is still outside the internal network.

Host firewalls and microsegmentation

Rules on each device, so even machines in the same subnet are separated from each other. Common on servers and in virtualised data centres.

Cloud segmentation

Virtual networks, subnets and security groups do the same job in cloud networks.

VLANs, conceptually

VLANs deserve a closer look because they are the most common segmentation tool. Without VLANs, five segments would need five sets of switches. With VLANs, one switch can carry all five: the administrator assigns each port to a VLAN, and the switch never forwards frames between VLANs. Each VLAN is its own broadcast domain. A link that carries several VLANs between switches (a trunk) tags each frame with its VLAN number, so the VLANs stay separate.

Remember: a VLAN separates devices, but it doesn't decide what may cross. If the device that routes between VLANs simply allows everything, you have several subnets but the security of one flat network. The rules on that routing device are what make segmentation a security control.

Going further (CCNA): how to create VLANs, assign ports and configure trunks on Cisco switches is covered in the CCNA lesson VLANs and trunks. You don't need it for this course.

Guest networks

Guest Wi-Fi is the simplest form of segmentation most people use. The access point broadcasts a second network name (SSID) that is mapped to its own segment, 192.168.50.0/24, with its own DHCP range. The firewall allows guests to reach the internet and denies everything towards internal subnets. Good guest networks also turn on client isolation, so guests can't reach each other either.

Learn more: Wireless Security

The DMZ

A DMZ (demilitarised zone) is a segment for systems that must accept connections from the internet: a public website, a mail gateway, a VPN portal. Because they are exposed, they are the most likely to be attacked, so they are kept out of the internal network. A typical rule set says:

  • The internet may reach the DMZ on a few ports only.
  • The DMZ may reach the inside only on very specific ports, for example from the web server to the database.
  • The inside network may manage the DMZ.

Example: segmenting a small office

Here is a 60-person office that has been redesigned from one flat network into seven segments. The firewall is the default gateway (.1) in every segment.

SegmentSubnetWho lives thereTrust
Staff192.168.10.0/24Staff laptops and desktopsMedium
Servers192.168.30.0/24File server, database, intranetHigh
Printers & IoT192.168.40.0/24Printers, cameras, door controllers, smart TVsLow
Guest Wi-Fi192.168.50.0/24Visitors' phones and laptopsNone
Management192.168.99.0/24Admin interfaces of switches, access points, firewallHighest
VPN users10.8.0.0/24Remote staff connected through the VPNMedium
DMZ172.16.1.0/24Public web serverLow (exposed to the internet)

Next come the allowed flows. Anything not listed is blocked by the implicit deny at the end of the rule list.

FromToServiceDecision
StaffInternetWeb (TCP 80, 443), DNS✅ Allow
StaffServersFile sharing (TCP 445), intranet (TCP 443)✅ Allow
StaffPrinters & IoTPrinting only (TCP 9100, 631)✅ Allow
VPN usersServersFile sharing and intranet only✅ Allow
Guest Wi-FiInternetWeb and DNS✅ Allow
Guest Wi-FiAny internal segmentAnything❌ Deny (and log)
Printers & IoTStaff or ServersAnything❌ Deny (and log)
InternetDMZHTTPS (TCP 443) to the web server✅ Allow
DMZServersOnly the web server to the database port✅ Allow
InternetAny internal segmentAnything❌ Deny (and log)
IT admin PCsManagementSSH, HTTPS✅ Allow
Everyone elseManagementAnything❌ Deny (and log)
outsideInternetDMZWeb serverDMZ 172.16.1.10Firewallgateway .1 in every segmentStaffStaff laptop192.168.10.23ServersFile server192.168.30.10IoTPrinter192.168.40.20GuestGuest phone192.168.50.31
  1. 1. Staff → Servers, file sharing: allowed. The laptop sends the packet to its default gateway. The firewall matches the Staff → Servers rule and routes it.
  2. 2. Staff → Printers, printing: allowed. Only the printing ports are open, so staff can't reach the printer's admin page.
  3. 3. Guest → Internet: allowed. Visitors get internet access, which is all they need.
  4. 4. Guest → Servers: denied. The guest network can't reach anything internal. The attempt is logged.
  5. 5. Printer → Staff: denied. If the printer is ever compromised, it can't be used to attack staff laptops.
  6. 6. Internet → DMZ web server: allowed. The only way in from the internet leads to the DMZ, not to the internal network.
Each device's default gateway is the firewall, so every flow between segments is checked against the allowed-flows table.

Designing your own segments

  1. List the groups of devices and people: staff, servers, guests, IoT devices and admin interfaces.
  2. Rank their trust. Anything you can't patch or control, such as IoT devices and guests, gets low trust.
  3. Write down the flows each group really needs. Ask the application owners which ports their applications use.
  4. Give each segment its own subnet (and usually its own VLAN and DHCP scope). The Subnet Calculator helps you plan the ranges.
  5. Make the firewall the default gateway for each segment, allow only the listed flows, and log everything that is denied.
  6. Watch the logs for a few weeks. Add rules for genuine needs you missed, and question everything else.

What happens when segmentation goes wrong

ProblemResult
“Allow any → any” between internal segmentsMany subnets, but the security of a flat network
A device plugged into a port in the wrong segmentIt gets an address in the wrong subnet from DHCP, so it either can't work or can reach things it shouldn't
Guest Wi-Fi mapped to the staff segment by mistakeVisitors can reach internal servers
An application flow forgotten in the designThe application breaks after the change; users see timeouts
Management interfaces reachable from every segmentAn attacker on any PC can try to log in to the switches and firewall
The firewall between segments failsAll traffic between segments stops; traffic inside each segment keeps working

Troubleshooting and useful commands

Start by checking which segment a device is actually in:

Example output from a Windows PC (excerpt), written for this lesson
C:\> ipconfig
Ethernet adapter Ethernet:

   Connection-specific DNS Suffix  . : office.example
   IPv4 Address. . . . . . . . . . . : 192.168.10.23
   Subnet Mask . . . . . . . . . . . : 255.255.255.0
   Default Gateway . . . . . . . . . : 192.168.10.1

What to look for: IPv4 Address 192.168.10.23 with a 255.255.255.0 (/24) Subnet Mask and Default Gateway 192.168.10.1 means this PC is in the Staff segment. If a staff PC shows a 192.168.50.x address, it is plugged into a guest port or has joined the guest Wi-Fi.

Then check whether traffic crosses the firewall, and where it stops. The -d option skips name lookups, so the output shows only IP addresses:

Example output from a Windows PC in the Guest segment, written for this lesson
C:\> tracert -d 192.168.30.10
Tracing route to 192.168.30.10 over a maximum of 30 hops

  1     2 ms     1 ms     1 ms  192.168.50.1
  2     *        *        *     Request timed out.
  3     *        *        *     Request timed out.
  4     *        *        *     Request timed out.
^C

What to look for: hop 1, 192.168.50.1, is the firewall's guest interface. After that, every hop shows Request timed out: the firewall silently drops guest traffic to the server segment, as designed. From a staff PC, the same command would show 192.168.10.1 as hop 1 and the server itself as hop 2.

Finally, test the exact service a user needs:

Example output from a Windows PC in the Staff segment, written for this lesson
PS C:\> Test-NetConnection 192.168.30.10 -Port 445
ComputerName     : 192.168.30.10
RemoteAddress    : 192.168.30.10
RemotePort       : 445
InterfaceAlias   : Ethernet
SourceAddress    : 192.168.10.23
TcpTestSucceeded : True

What to look for: TcpTestSucceeded : True means the Staff → Servers file-sharing flow works. SourceAddress confirms the test came from the Staff subnet. If the result were False, check the firewall log for a deny between those two subnets, then check the host firewall on the server.

Common mistakes

  • Creating VLANs and then allowing everything between them. This gives separation without control, so an attacker can still move freely between segments.
  • Putting IoT devices in the staff segment. Cameras and printers are often old and unpatched, so they belong in a low-trust segment.
  • Forgetting the management network. The admin pages of switches, access points and the firewall should be reachable only from IT admin PCs.
  • Creating too many tiny segments at once. Start with a few clear zones; complex designs lead to mistakes.
  • Treating VPN users as fully trusted. Give VPN users their own segment and only the access they need.
  • Not logging denied flows. The logs are how you notice both a missing rule and an attacker.
✅ Key takeaways
  • Segmentation splits a network into zones and controls the traffic between them.
  • It limits the blast radius of an incident and makes lateral movement harder.
  • Traffic inside one subnet never passes through the firewall, so segments must be separate subnets for its rules to apply.
  • Common tools: subnets, VLANs, firewalls between zones, guest networks, a DMZ and host firewalls.
  • A VLAN separates devices; the firewall rules between VLANs provide the security.
  • To design segments, list the groups, rank their trust, allow only the flows they need and log the rest.

Knowledge check

Predict · scenario 1

Two PCs are both in 192.168.10.0/24. A firewall rule says 'deny Staff → Staff'. Can the firewall stop them communicating?

Predict · scenario 2

An office puts staff in VLAN 10 and printers in VLAN 40 on separate subnets, but the firewall between them allows any → any. A hacked printer scans staff laptops. What happens?

Predict · scenario 3

Ransomware infects a laptop on guest Wi-Fi. The guest segment may only reach the internet. Which is most likely protected?

Predict · scenario 4

A company is launching a public website on its own server, which must accept connections from the internet. Which segment should the server go in?

Where to go next

You now know the four pillars of network security covered in this course: the principles in Basic network security, the rules in Firewall basics, protected paths with VPN basics, and the zones in this lesson. Next, the course puts everything together and follows packets end to end, starting with Same-subnet communication.

FAQ

Is a VLAN the same as network segmentation?
No. A VLAN is one way to segment: it splits one physical switch into several separate LANs. On its own, a VLAN only separates the networks. The security comes from what you allow between them, usually with firewall rules on the device that routes between the VLANs.
Does segmentation slow the network down?
Very little in practice. Traffic inside a segment is not affected. Traffic between segments passes through a firewall or a Layer 3 switch, which adds a small delay. Smaller segments also mean smaller broadcast domains, which can make the network run more smoothly.
Do home networks need segmentation?
A simple version helps. Put visitors and smart-home devices on the router's guest Wi-Fi, so they can reach the internet but not your laptops and file shares. Many home routers support this with a single setting.
What is microsegmentation?
Microsegmentation takes segmentation down to individual machines. Each server or workload gets its own rules, usually enforced by host firewalls or by the virtualisation or cloud platform. Even two servers in the same subnet can then only communicate if a rule allows it.