Network segmentation and microsegmentation: the zones a mid-size company needs and where to start
Eurokommerz, Vienna, since 2006: Private AI/ML · IT Managed Services · Enterprise Training · AI Hardware & Software
- Network segmentation splits a network into zones, such as users, servers, management, backup, OT and guests, and filters the traffic between them, usually on a firewall; microsegmentation applies rules inside a zone, down to one application or virtual machine, enforced close to the workload, usually on the host or in the hypervisor
- A VLAN separates broadcast domains but does not filter traffic; VLANs become segmentation where a firewall or the routing switch’s access control lists decide what passes between them, and traffic inside a VLAN needs host or hypervisor rules
- The NSA calls data flow mapping “foundational” for macro and micro segmentation, and CISA’s guidance of 29 July 2025 starts from candidates and their dependencies and tests new rules, for example in a permissive mode that flags violations, before enforcing them
- The NSX distributed firewall’s catch-all default rule is set to allow after host preparation, and Broadcom’s documentation, updated 1 October 2026, calls changing it to block “a best practice”
- Point 6.8 of Implementing Regulation (EU) 2024/2690 asks for a DMZ, a separate administration network, communications restricted between and within zones, production apart from development and testing, and reviews at planned intervals; it binds only the providers in its Article 1
Eurokommerz × Vixen.UNO: Cyber Resilience Talk to an expert →
Network segmentation vs microsegmentation
Network segmentation divides a network into zones and lets traffic between them pass only through a filtering point, usually a firewall, that allows what the business needs and blocks the rest. Microsegmentation applies the same principle inside a zone, down to one application or virtual machine, with rules enforced close to the workload: on the host, in the hypervisor or at a gateway in front of a few systems. For a company of 200 to 2,000 staff, a workable order is zones first, with default deny between them, then microsegmentation where east-west traffic carries the most risk: the server, management and backup zones.
CISA’s “Microsegmentation in Zero Trust Part One” of 29 July 2025 describes macrosegmentation as dividing a network “into multiple discrete chunks that support various business needs” and says microsegmentation “builds upon” it. The NSA’s guidance on the network and environment pillar (March 2024) describes the finer level by department: “employees in the same department should not have access to each other’s resources unless explicitly required”.
East-west traffic, in Broadcom’s vDefend terminology, “flows laterally between applications that run on virtual machines, bare metal servers, or containers”. North-south traffic enters or leaves the data centre. A network that places all servers in one segment, CISA notes, makes them “potentially accessible by any compromised organization endpoint”. Our guide to zero trust for a mid-size company shows where segmentation fits after identity, devices and privileged access.
The zones a mid-size company needs
A zone groups systems with the same function and trust level, whatever VLANs, subnets or sites they use. At the basic stage of the NSA’s maturity model, organisations begin segmenting “based on business functions, locations, and asset criticality”. The allowed flows in the table are a starting point that the flow map confirms or corrects.
| ZONE | WHAT LIVES THERE | ALLOWED FLOWS |
|---|---|---|
| Users | workstations and laptops, in the office and on VPN | to published applications, infrastructure services and the web filter; no traffic between workstations |
| DMZ | reverse proxy, mail gateway, remote access gateways | from the internet to published ports; to named back-end servers only |
| Servers by tier | web, application and database servers, one segment per tier | users to the front tier; each tier to the next; databases from the application tier and backup only |
| Infrastructure services | domain controllers, DNS, NTP, certificate, patch and log servers | from every zone except guests, on the service ports only; DMZ and OT through relays or their own services |
| Management | hypervisors and vCenter, BMCs, network and storage management, jump hosts, in separate segments | from jump hosts and administration workstations only |
| Backup | backup servers, proxies and repositories | to the systems they protect and the repositories; consoles from the management zone only |
| Development and test | development and test systems | no path to production data; one named deployment path |
| OT and production | machine controllers, SCADA, building automation | to named IT systems through a DMZ; no direct traffic to the office network or the internet |
| Guests and IoT devices | guest Wi-Fi; printers, cameras, door controllers, in separate segments | guests to the internet only; devices only to and from the servers that manage them |
| Third-party access | suppliers’ remote sessions | to named systems after authorisation, for a set time, logged |
Our design summary. The DMZ, management, development and supplier rows follow Implementing Regulation (EU) 2024/2690, Annex points 6.7.2 and 6.8.2; the OT row follows NIST SP 800-82 Rev. 3 (September 2023).
Administration of every zone comes from the management zone, and nearly every zone uses infrastructure services, so both rule sets are written once, before any zone moves to default deny. For OT, IoT and legacy devices, CISA notes that “agent-based segmentation solutions may not be available”, which leaves network-based segmentation. GPU servers add storage and cluster segments, as our guide to securing a GPU server describes.
Our Cyber Resilience service segments the network and sets up zero-trust access. Send us your current VLAN and subnet list, with the device that routes between them, through the form below.
VLAN segmentation: VLANs, firewalls and switch ACLs
A VLAN separates broadcast domains at layer 2 but does not filter traffic. Traffic between VLANs is routed, and the device that routes it decides whether they form a security boundary: a core switch that routes between all VLANs without filters joins them into one network again. For VLANs to count as segmentation, each zone’s gateway sits on a firewall, or the routing switch applies access control lists.
A stateful firewall tracks each connection and admits the replies, while a stateless access control list must permit return traffic explicitly, which tends to widen the rules. NIST SP 800-207 says some features of microsegmentation can be built with “less advanced gateway devices and even stateless firewalls”, but the administration cost and the difficulty of adapting quickly to changes make this “a very poor choice”.
On the switches, configure trunks explicitly, each carrying only the VLANs it needs, and set every other port to access mode with trunk negotiation off; shut unused ports and give trunks a native VLAN that no access port uses. These settings block VLAN hopping by trunk negotiation or by double-tagged frames. Route the management VLANs in a separate routing instance (VRF) whose only exit is the firewall.
Where microsegmentation is enforced: network, host or hypervisor
NIST SP 800-207 (August 2020) describes two ways to build microsegmentation: gateways such as “intelligent switches (or routers) or next generation firewalls (NGFWs)” in front of each resource or small group of related resources, or “host-based micro-segmentation using software agents” or firewalls on the endpoints. A host-based firewall that allows only necessary traffic also protects a server from hosts “on the same subnet”, notes NIST SP 800-41 Rev. 1 (September 2009). In a virtualised data centre the hypervisor adds a third place: NIST SP 800-125B (March 2016) describes kernel-based firewalls filtering “between the vNICs of each VM and the hypervisor switch”, with rules that move with the VM when it migrates.
| METHOD | FILTERS AT | GRANULARITY | LIMITS |
|---|---|---|---|
| VLANs and a firewall | the firewall routing between VLANs | zone, subnet | no filtering inside a VLAN; VM traffic between VLANs on one host leaves the host and returns |
| Switch ACLs | the layer 3 switch | subnet, address, port | often stateless; address rules are hard to keep current |
| Host firewall or agent | each host’s operating system | host, port, process | needs central management; no agent for many OT, IoT and legacy devices |
| Distributed firewall | each VM’s vNIC, in the hypervisor | VM, group, tag | VMs on prepared hosts only; physical servers need an agent or another method |
NIST SP 800-207, SP 800-41 Rev. 1 and SP 800-125B; CISA, Microsegmentation in Zero Trust Part One (29 July 2025); Broadcom vDefend Firewall 9.0 documentation (1 October 2026).
In a vSphere estate with NSX, the distributed firewall is the hypervisor option. Broadcom’s vDefend documentation, updated 1 October 2026, says it is “deployed on each ESXi host workload to segment east-west traffic”, and it can be enabled on the port groups of an existing vSphere Distributed Switch. After host preparation its catch-all default rule allows traffic, and Broadcom calls it “a best practice to then change this default rule to block action”. Licensing and rule design are in our guide to the NSX distributed firewall and vDefend. Its management and control plane belongs in the management zone, since the NSA warns that an SDN controller “can become a priority target”.
Map the east-west flows before writing rules
The NSA calls data flow mapping “foundational for other network activities, such as macro and micro segmentation”. CISA’s four phases start the same way: identify candidates, identify their dependencies, decide the policy, then deploy and validate it. For a running system, CISA suggests building the first dependency list “through tracking the communications of the transition candidate”.
Firewall logs show what already crosses zone boundaries (where the allow rules log), flow records (NetFlow or IPFIX) from core switches and routers show routed traffic, and the flow view of a hypervisor or distributed firewall shows traffic between VMs; application owners supply the reasons. Record source, destination, protocol, port, owner and reason for each flow, and collect for at least one full monthly cycle. Ask about quarterly and yearly jobs, such as year-end closing and the disaster recovery test, which a short capture misses. A flow that no owner can explain is a candidate for removal, after one more question to its operators.
Default deny inside the data centre, step by step
NIST SP 800-41 Rev. 1 says that, generally, traffic “not expressly permitted by the firewall policy should be blocked”. Get there one zone or application at a time, with a logging stage before anything is blocked.
- Pick the first candidate: the management zone, or one critical application whose owner takes part.
- Write the shared rules for infrastructure services (DNS, NTP, authentication, patching, logging, backup) once, for all zones.
- Write the candidate’s allow rules from the flow map, by group or tag where the platform allows.
- End the candidate’s rules with a catch-all rule scoped to it alone. Set it to allow and log, a permissive mode which, in CISA’s words, “flags policy violations to detect potentially missed dependencies”.
- After at least one monthly cycle, turn every legitimate hit into an allow rule with an owner.
- Switch the candidate’s catch-all rule to deny in an agreed maintenance window and tell users where to report problems; the rollback is the same rule back to allow.
- Check from a host in another zone that only the allowed ports answer, move to the next candidate, and review the rule set at planned intervals and after significant changes.
Switch a platform-wide default rule, such as the NSX default rule, to deny last, once every zone has its own rules. CISA also asks for published documentation of “the current enforcement level” and a feedback channel for users.
Under our Cyber Resilience service, our engineering partner Vixen.UNO rolls out such changes step by step, in agreed maintenance windows with a rollback plan. Describe the zone you would close first and the firewalls between your zones today.
Management, backup, OT and supplier access
The management zone controls all the others. For the providers it covers, Implementing Regulation 2024/2690 asks for a dedicated administration network apart from the operational network, administration channels segregated from other traffic (Annex points 6.8.2(f) and (g)) and administration systems used for nothing else (11.4.2(a)). Jump hosts and administration workstations are then the only sources of administrative traffic. Our guide to hardening ESXi hosts and vCenter against ransomware covers the vSphere side.
Backup consoles answer only from the management zone, and repositories accept connections only from the backup infrastructure. For OT, NIST SP 800-82 Rev. 3 (September 2023) recommends a DMZ architecture with firewalls “to prevent network traffic from passing directly between the corporate and OT networks”.
For suppliers, point 6.7.2(h) allows service providers to connect “only after an authorisation request and for a set time period, such as the duration of a maintenance operation”. Their sessions end in the third-party access zone.
Implementing Regulation 2024/2690 point 6.8 as a reference
Implementing Regulation (EU) 2024/2690, which sets out network segmentation in point 6.8 of its Annex, binds only the providers listed in its Article 1, such as cloud, data centre and managed service providers; other companies can use it as a reference. Recital 89 of NIS2 lists network segmentation among basic cyber hygiene practices. Whether NIS2 applies to a company is a legal assessment for its legal department. Our overview of NIS2 Article 21 and the evidence behind each measure covers the other measures.
Point 6.8.1 ties the zones to the risk assessment and asks for segmentation from third parties. Point 6.8.2 asks the entities to consider “the functional, logical and physical relationship, including location” between systems, to keep critical systems in secured zones, to deploy a DMZ and to restrict communications “between and within zones” to what operation or safety needs, which reaches into microsegmentation. It also asks them to separate the administration network, segregate administration channels and separate production systems “from systems used in development and testing, including backups”. Point 6.8.3 adds reviews “at planned intervals” and after significant incidents or changes, and 6.7.2(a) a network architecture documented “in a comprehensible and up to date manner”.
What we do
Under Cyber Resilience, our engineering partner Vixen.UNO sets up network segmentation and zero-trust access, and firewalls, intrusion prevention (IPS) and email and web traffic filtering on Trend Micro, Cisco and other vendors’ solutions. An assessment of infrastructure, access and backups gives you a risk map and a prioritised action plan; changes follow step by step in agreed maintenance windows, with a rollback plan. For NSX, our VMware optimisation service modernises vSphere, vSAN and NSX in agreed maintenance windows. Eurokommerz holds the contract; the first call is free of charge, and the price of the technical assessment is fixed before work begins.
FAQ
What is the difference between network segmentation and microsegmentation?
What are network segmentation best practices?
What is east-west traffic?
Is VLAN segmentation enough for security?
How do you implement microsegmentation?
Does NIS2 require network segmentation?
Send us your VLAN and subnet list, the device that routes and filters between them, how administrators and suppliers connect today, and which systems you would protect first. We reply within one business day to arrange a first call, from which you leave with two or three possible solution scenarios. The first call is free of charge.
Talk to an expertWe reply within one business day