BLOG · GUIDE ·

Network segmentation and microsegmentation: the zones a mid-size company needs and where to start

Eurokommerz, Vienna, since 2006: Private AI/ML · IT Managed Services · Enterprise Training · AI Hardware & Software

IN BRIEF
  • Network segmentation splits a network into zones, such as users, servers, management, backup, OT and guests, and filters the traffic between them, usually on a firewall; microsegmentation applies rules inside a zone, down to one application or virtual machine, enforced close to the workload, usually on the host or in the hypervisor
  • A VLAN separates broadcast domains but does not filter traffic; VLANs become segmentation where a firewall or the routing switch’s access control lists decide what passes between them, and traffic inside a VLAN needs host or hypervisor rules
  • The NSA calls data flow mapping “foundational” for macro and micro segmentation, and CISA’s guidance of 29 July 2025 starts from candidates and their dependencies and tests new rules, for example in a permissive mode that flags violations, before enforcing them
  • The NSX distributed firewall’s catch-all default rule is set to allow after host preparation, and Broadcom’s documentation, updated 1 October 2026, calls changing it to block “a best practice”
  • Point 6.8 of Implementing Regulation (EU) 2024/2690 asks for a DMZ, a separate administration network, communications restricted between and within zones, production apart from development and testing, and reviews at planned intervals; it binds only the providers in its Article 1

Eurokommerz × Vixen.UNO: Cyber Resilience  Talk to an expert →

Network segmentation vs microsegmentation

Network segmentation divides a network into zones and lets traffic between them pass only through a filtering point, usually a firewall, that allows what the business needs and blocks the rest. Microsegmentation applies the same principle inside a zone, down to one application or virtual machine, with rules enforced close to the workload: on the host, in the hypervisor or at a gateway in front of a few systems. For a company of 200 to 2,000 staff, a workable order is zones first, with default deny between them, then microsegmentation where east-west traffic carries the most risk: the server, management and backup zones.

CISA’s “Microsegmentation in Zero Trust Part One” of 29 July 2025 describes macrosegmentation as dividing a network “into multiple discrete chunks that support various business needs” and says microsegmentation “builds upon” it. The NSA’s guidance on the network and environment pillar (March 2024) describes the finer level by department: “employees in the same department should not have access to each other’s resources unless explicitly required”.

East-west traffic, in Broadcom’s vDefend terminology, “flows laterally between applications that run on virtual machines, bare metal servers, or containers”. North-south traffic enters or leaves the data centre. A network that places all servers in one segment, CISA notes, makes them “potentially accessible by any compromised organization endpoint”. Our guide to zero trust for a mid-size company shows where segmentation fits after identity, devices and privileged access.

The zones a mid-size company needs

A zone groups systems with the same function and trust level, whatever VLANs, subnets or sites they use. At the basic stage of the NSA’s maturity model, organisations begin segmenting “based on business functions, locations, and asset criticality”. The allowed flows in the table are a starting point that the flow map confirms or corrects.

ZONEWHAT LIVES THEREALLOWED FLOWS
Usersworkstations and laptops, in the office and on VPNto published applications, infrastructure services and the web filter; no traffic between workstations
DMZreverse proxy, mail gateway, remote access gatewaysfrom the internet to published ports; to named back-end servers only
Servers by tierweb, application and database servers, one segment per tierusers to the front tier; each tier to the next; databases from the application tier and backup only
Infrastructure servicesdomain controllers, DNS, NTP, certificate, patch and log serversfrom every zone except guests, on the service ports only; DMZ and OT through relays or their own services
Managementhypervisors and vCenter, BMCs, network and storage management, jump hosts, in separate segmentsfrom jump hosts and administration workstations only
Backupbackup servers, proxies and repositoriesto the systems they protect and the repositories; consoles from the management zone only
Development and testdevelopment and test systemsno path to production data; one named deployment path
OT and productionmachine controllers, SCADA, building automationto named IT systems through a DMZ; no direct traffic to the office network or the internet
Guests and IoT devicesguest Wi-Fi; printers, cameras, door controllers, in separate segmentsguests to the internet only; devices only to and from the servers that manage them
Third-party accesssuppliers’ remote sessionsto named systems after authorisation, for a set time, logged

Our design summary. The DMZ, management, development and supplier rows follow Implementing Regulation (EU) 2024/2690, Annex points 6.7.2 and 6.8.2; the OT row follows NIST SP 800-82 Rev. 3 (September 2023).

Administration of every zone comes from the management zone, and nearly every zone uses infrastructure services, so both rule sets are written once, before any zone moves to default deny. For OT, IoT and legacy devices, CISA notes that “agent-based segmentation solutions may not be available”, which leaves network-based segmentation. GPU servers add storage and cluster segments, as our guide to securing a GPU server describes.

Our Cyber Resilience service segments the network and sets up zero-trust access. Send us your current VLAN and subnet list, with the device that routes between them, through the form below.

VLAN segmentation: VLANs, firewalls and switch ACLs

A VLAN separates broadcast domains at layer 2 but does not filter traffic. Traffic between VLANs is routed, and the device that routes it decides whether they form a security boundary: a core switch that routes between all VLANs without filters joins them into one network again. For VLANs to count as segmentation, each zone’s gateway sits on a firewall, or the routing switch applies access control lists.

A stateful firewall tracks each connection and admits the replies, while a stateless access control list must permit return traffic explicitly, which tends to widen the rules. NIST SP 800-207 says some features of microsegmentation can be built with “less advanced gateway devices and even stateless firewalls”, but the administration cost and the difficulty of adapting quickly to changes make this “a very poor choice”.

On the switches, configure trunks explicitly, each carrying only the VLANs it needs, and set every other port to access mode with trunk negotiation off; shut unused ports and give trunks a native VLAN that no access port uses. These settings block VLAN hopping by trunk negotiation or by double-tagged frames. Route the management VLANs in a separate routing instance (VRF) whose only exit is the firewall.

Where microsegmentation is enforced: network, host or hypervisor

NIST SP 800-207 (August 2020) describes two ways to build microsegmentation: gateways such as “intelligent switches (or routers) or next generation firewalls (NGFWs)” in front of each resource or small group of related resources, or “host-based micro-segmentation using software agents” or firewalls on the endpoints. A host-based firewall that allows only necessary traffic also protects a server from hosts “on the same subnet”, notes NIST SP 800-41 Rev. 1 (September 2009). In a virtualised data centre the hypervisor adds a third place: NIST SP 800-125B (March 2016) describes kernel-based firewalls filtering “between the vNICs of each VM and the hypervisor switch”, with rules that move with the VM when it migrates.

METHODFILTERS ATGRANULARITYLIMITS
VLANs and a firewallthe firewall routing between VLANszone, subnetno filtering inside a VLAN; VM traffic between VLANs on one host leaves the host and returns
Switch ACLsthe layer 3 switchsubnet, address, portoften stateless; address rules are hard to keep current
Host firewall or agenteach host’s operating systemhost, port, processneeds central management; no agent for many OT, IoT and legacy devices
Distributed firewalleach VM’s vNIC, in the hypervisorVM, group, tagVMs on prepared hosts only; physical servers need an agent or another method

NIST SP 800-207, SP 800-41 Rev. 1 and SP 800-125B; CISA, Microsegmentation in Zero Trust Part One (29 July 2025); Broadcom vDefend Firewall 9.0 documentation (1 October 2026).

In a vSphere estate with NSX, the distributed firewall is the hypervisor option. Broadcom’s vDefend documentation, updated 1 October 2026, says it is “deployed on each ESXi host workload to segment east-west traffic”, and it can be enabled on the port groups of an existing vSphere Distributed Switch. After host preparation its catch-all default rule allows traffic, and Broadcom calls it “a best practice to then change this default rule to block action”. Licensing and rule design are in our guide to the NSX distributed firewall and vDefend. Its management and control plane belongs in the management zone, since the NSA warns that an SDN controller “can become a priority target”.

Map the east-west flows before writing rules

The NSA calls data flow mapping “foundational for other network activities, such as macro and micro segmentation”. CISA’s four phases start the same way: identify candidates, identify their dependencies, decide the policy, then deploy and validate it. For a running system, CISA suggests building the first dependency list “through tracking the communications of the transition candidate”.

Firewall logs show what already crosses zone boundaries (where the allow rules log), flow records (NetFlow or IPFIX) from core switches and routers show routed traffic, and the flow view of a hypervisor or distributed firewall shows traffic between VMs; application owners supply the reasons. Record source, destination, protocol, port, owner and reason for each flow, and collect for at least one full monthly cycle. Ask about quarterly and yearly jobs, such as year-end closing and the disaster recovery test, which a short capture misses. A flow that no owner can explain is a candidate for removal, after one more question to its operators.

Default deny inside the data centre, step by step

NIST SP 800-41 Rev. 1 says that, generally, traffic “not expressly permitted by the firewall policy should be blocked”. Get there one zone or application at a time, with a logging stage before anything is blocked.

  1. Pick the first candidate: the management zone, or one critical application whose owner takes part.
  2. Write the shared rules for infrastructure services (DNS, NTP, authentication, patching, logging, backup) once, for all zones.
  3. Write the candidate’s allow rules from the flow map, by group or tag where the platform allows.
  4. End the candidate’s rules with a catch-all rule scoped to it alone. Set it to allow and log, a permissive mode which, in CISA’s words, “flags policy violations to detect potentially missed dependencies”.
  5. After at least one monthly cycle, turn every legitimate hit into an allow rule with an owner.
  6. Switch the candidate’s catch-all rule to deny in an agreed maintenance window and tell users where to report problems; the rollback is the same rule back to allow.
  7. Check from a host in another zone that only the allowed ports answer, move to the next candidate, and review the rule set at planned intervals and after significant changes.

Switch a platform-wide default rule, such as the NSX default rule, to deny last, once every zone has its own rules. CISA also asks for published documentation of “the current enforcement level” and a feedback channel for users.

Under our Cyber Resilience service, our engineering partner Vixen.UNO rolls out such changes step by step, in agreed maintenance windows with a rollback plan. Describe the zone you would close first and the firewalls between your zones today.

Management, backup, OT and supplier access

The management zone controls all the others. For the providers it covers, Implementing Regulation 2024/2690 asks for a dedicated administration network apart from the operational network, administration channels segregated from other traffic (Annex points 6.8.2(f) and (g)) and administration systems used for nothing else (11.4.2(a)). Jump hosts and administration workstations are then the only sources of administrative traffic. Our guide to hardening ESXi hosts and vCenter against ransomware covers the vSphere side.

Backup consoles answer only from the management zone, and repositories accept connections only from the backup infrastructure. For OT, NIST SP 800-82 Rev. 3 (September 2023) recommends a DMZ architecture with firewalls “to prevent network traffic from passing directly between the corporate and OT networks”.

For suppliers, point 6.7.2(h) allows service providers to connect “only after an authorisation request and for a set time period, such as the duration of a maintenance operation”. Their sessions end in the third-party access zone.

Implementing Regulation 2024/2690 point 6.8 as a reference

Implementing Regulation (EU) 2024/2690, which sets out network segmentation in point 6.8 of its Annex, binds only the providers listed in its Article 1, such as cloud, data centre and managed service providers; other companies can use it as a reference. Recital 89 of NIS2 lists network segmentation among basic cyber hygiene practices. Whether NIS2 applies to a company is a legal assessment for its legal department. Our overview of NIS2 Article 21 and the evidence behind each measure covers the other measures.

Point 6.8.1 ties the zones to the risk assessment and asks for segmentation from third parties. Point 6.8.2 asks the entities to consider “the functional, logical and physical relationship, including location” between systems, to keep critical systems in secured zones, to deploy a DMZ and to restrict communications “between and within zones” to what operation or safety needs, which reaches into microsegmentation. It also asks them to separate the administration network, segregate administration channels and separate production systems “from systems used in development and testing, including backups”. Point 6.8.3 adds reviews “at planned intervals” and after significant incidents or changes, and 6.7.2(a) a network architecture documented “in a comprehensible and up to date manner”.

What we do

Under Cyber Resilience, our engineering partner Vixen.UNO sets up network segmentation and zero-trust access, and firewalls, intrusion prevention (IPS) and email and web traffic filtering on Trend Micro, Cisco and other vendors’ solutions. An assessment of infrastructure, access and backups gives you a risk map and a prioritised action plan; changes follow step by step in agreed maintenance windows, with a rollback plan. For NSX, our VMware optimisation service modernises vSphere, vSAN and NSX in agreed maintenance windows. Eurokommerz holds the contract; the first call is free of charge, and the price of the technical assessment is fixed before work begins.

FAQ

What is the difference between network segmentation and microsegmentation?
Network segmentation divides a network into zones, such as users, servers, management and guests, and filters the traffic between zones, usually on a firewall. Microsegmentation applies rules inside a zone, down to one application or one virtual machine, enforced close to the workload, usually on the host or in the hypervisor. CISA’s guidance of July 2025 describes microsegmentation as building on macrosegmentation, the coarser zone-level form.
What are network segmentation best practices?
Define zones by function and trust level, put a filtering point between them and allow only the flows the business needs, with a catch-all deny at the end. Map the existing flows before writing rules, keep administration in a separate management zone reached only from jump hosts and administration workstations, and give suppliers time-limited access to named systems only. Review the rules at planned intervals and after significant changes, as Implementing Regulation (EU) 2024/2690 asks of the providers it covers.
What is east-west traffic?
East-west traffic flows laterally between servers, virtual machines or containers inside the data centre, while north-south traffic enters or leaves it. A firewall at the internet edge filters north-south traffic, so traffic between servers goes unchecked unless internal firewalls filter it between segments and host or hypervisor firewalls within a segment.
Is VLAN segmentation enough for security?
A VLAN separates broadcast domains but does not filter traffic by itself; the device that routes between VLANs decides what may pass. VLANs become segmentation when the gateway of each zone sits on a firewall, or the routing switch applies access control lists, with rules that allow only the needed flows. Traffic between hosts in the same VLAN reaches neither, so it needs host or hypervisor firewalls.
How do you implement microsegmentation?
Start with one candidate application or zone, map its flows and dependencies, and write allow rules, by group or tag where the platform supports it. End the candidate’s rules with its own catch-all rule in a permissive, log-only mode to find missed dependencies, as CISA describes, then switch it to deny in a maintenance window with a rollback prepared. Repeat application by application, and switch a platform-wide default rule to deny only when every zone has its own rules.
Does NIS2 require network segmentation?
Article 21(2) of NIS2 does not name network segmentation, but recital 89 lists it among the basic cyber hygiene practices that essential and important entities should adopt, and Implementing Regulation (EU) 2024/2690 details it in point 6.8 of its Annex, under Article 21(2)(e). The regulation binds only the DNS, cloud, data centre, managed service and other digital providers listed in its Article 1, and other companies can use it as a reference. Whether NIS2 applies to a company is a legal assessment for its legal department.

Send us your VLAN and subnet list, the device that routes and filters between them, how administrators and suppliers connect today, and which systems you would protect first. We reply within one business day to arrange a first call, from which you leave with two or three possible solution scenarios. The first call is free of charge.

Talk to an expert
Talk to an expert

We reply within one business day

By sending this form you agree that we process your details to answer your enquiry – see our privacy policy.

request@eurokommerz.at
Jordangasse 7, 1010 Vienna