Network segmentation for organizations that have never done it

Network segmentation sounds expensive. Done right, it is mostly a matter of configuration on equipment you already own.

The four-VLAN minimum

  • Workstations. Where user laptops and desktops live.
  • Servers. Workstations may reach servers; servers do not initiate connections back to workstations.
  • IoT and printers. Cameras, printers, smart sensors, the conference room TV. Talks out to the internet and to specific server endpoints. That is it.
  • Guest. Internet only. Cannot see anything else on the network. Ever.

The staged rollout

Do not do it all at once. Roll out the guest VLAN first, then IoT, then split workstations from servers. Each phase is a discrete project with discrete acceptance criteria.

Related posts.