Example

Imagine a company has:

These VLANs segment the network. You can then use routing/firewall rules or ACLs to decide, for example, that Guest Wi-Fi can access the internet but cannot access the server VLAN.

So a good way to remember it is:

VLANs can provide network segmentation, but network segmentation isn’t limited to VLANs.

We can also segment networks using physical networks, subnets, firewalls, ACLs, VRFs, and other technologies.

Why physical segmentation can be attractive

If you have a highly sensitive network, putting it on completely separate physical infrastructure can reduce the ways an attacker can move between networks. For example:

Internet
|
Firewall
|
+---- Corporate network
|
+---- Separate physical network
|
+---- Critical systems

However, physical networks are more expensive and harder to manage.

We need additional switches, cables, network interfaces, potentially routers/firewalls, and so on.

VLANs are often preferred when we need to segment many networks because you can achieve substantial isolation without maintaining completely separate hardware.

So:

Physical segmentation can provide stronger isolation, especially for highly sensitive systems, while VLANs provide a more flexible and cost-effective way to segment networks.

Geef een reactie

Ontdek meer van Maikel van Esdonk

Abonneer je nu om meer te lezen en toegang te krijgen tot het volledige archief.

Lees verder