All references

Security

Network segmentation in the corporate network

Network components and structured cabling

Starting point

Users, servers and devices all sat in the same flat network. Broadcast traffic weighed on operations, and an incident on one device could have spread unchecked.

What we built

Analysis of the existing network, then a split into smaller, manageable segments using VLANs. Dedicated VLANs and subnets were created for user and device groups, assignments set cleanly, and communication between segments limited to what is actually needed.

Result

Access is controlled, broadcast domains are considerably smaller, and a security problem stays inside its segment instead of spreading across the network.