
Guide & Explainer
Network Segmentation – What is it? Why do you need it?
Segmentation separates network traffic; routing, firewall rules and access controls determine which systems can communicate. A VLAN alone does not guarantee security or more bandwidth.
Short answer
What to know
Segmentation separates network traffic; routing, firewall rules and access controls determine which systems can communicate. A VLAN alone does not guarantee security or more bandwidth.
Resource guide
The full explanation
Network segmentation divides a network into smaller physical or logical sections. VLANs are one way to separate traffic, but VLANs alone do not define which systems are allowed to communicate. Routing, firewall rules and access controls enforce that policy.
Segmentation controls how traffic flows between parts, being able to choose to prevent all traffic from one part from reaching another or to limit the flow by type of traffic, source, and destination. We call how you decide to segment a network segmentation policy.
But do you know how segmentation works?
Imagine a large bank with several branches and a policy restricting employee access to its financial reporting system.
After all, you don’t want your customer service employees snooping around your business’s accounting and financial side.
You can support this policy by allowing only the necessary connections to the financial system. The rule must be enforced at the points where traffic crosses between segments.
Some traditional technologies help enforce this segmentation policy, such as the famous internal firewalls, access control list (ACL), and virtual local area network (VLAN) configurations on network equipment.
For a hospital, separating visitor devices from medical systems can help limit unwanted communication. It does not create extra internet capacity or guarantee that medical devices will be unaffected by congestion.
Segmentation can limit an attacker’s movement between systems. It is one layer of security, and any effect on payment-security assessment scope must be validated for the actual environment.
Consider a surveillance system with several dozen cameras. Their combined traffic can be substantial, but bitrate varies with resolution, frame rate, compression and scene activity. A camera VLAN organizes that traffic; adequate switch capacity and uplinks still have to carry it.
That is why we plan segmentation and network capacity together instead of treating a VLAN as a guaranteed performance upgrade.
If you are having trouble with your network, please don’t hesitate to reach out. We’d be happy to run some site diagnostics and a plan to improve your network and security.
For help applying this to your facility, explore our network infrastructure services.
Need help applying this?
Start with the problem, not the product.
Tell 210 Solutions what is happening in your building and what you need the system to accomplish.