FREEIntermediate · 14 minute read

Network segmentation and Zero Trust

Limit unnecessary communication and make access decisions explicit across identities, devices and services.

WHAT YOU WILL LEARN

Learning objectives

  • Identify why flat networks increase exposure
  • Design a simple communication matrix
  • Validate segmentation rather than trusting labels
01

Map the flows before writing rules

List the applications, users, devices and services that need to communicate. Record the purpose, protocol and owner for each flow. Separate guest access, ordinary workstations, administration, servers and recovery systems where appropriate. A VLAN name alone is not proof of isolation; routing and filtering determine which traffic actually passes.

02

Allow required access, review exceptions

Use explicit rules based on business need. Administrative access should take a controlled route with strong identity and device requirements. Exceptions need an owner and an expiry or review date. Avoid a broad allow rule that quietly reconnects every segment.

03

Validate from representative locations

Use authorised tests to confirm required applications work and prohibited paths fail. Review logs and packet evidence within the agreed scope. Account for dependencies such as DNS and time services. Zero Trust is an approach to continually evaluating access, not a product label or the assumption that an internal address is trustworthy.

APPLIED EXAMPLE

Put it in context

A fictional small business separates guest Wi-Fi from its office network but finds a broad routing rule still permits server access. A controlled validation test exposes the gap before the design is treated as complete.

Illustrative scenario for learning, not a claim about a verified customer incident.

Common mistakes

  • Assuming VLANs automatically block routing
  • Trusting every internal device
  • Creating permanent unowned exceptions

Your practical checklist

Checklist ticks are temporary and are not recorded as account progress.

MINI RECAP

Segmentation limits movement only when the rules, routes and validation evidence match the intended design.

Put your understanding to the test.

OPTIONAL NEXT STEP · PRO

Test the reasoning behind a network boundary.

The released segmentation lab includes a synthetic network and rule review, allowed and denied paths, and worked decisions about proportionate controls.

See the segmentation lab →

Recurring membership. Both plans include the same available Pro collection. Compare the complete offer.

Already a member? Log in or manage your membership before purchasing again.

Free lessons, quizzes and Simulation A stay free.

Further authoritative reading ↗