top of page

News

Is Your Network Segmented — or Just Divided Into VLANs?

  • Writer: RoyceMedia
    RoyceMedia
  • 17 minutes ago
  • 3 min read
Network segmentation separating staff devices, servers, guest Wi-Fi, IoT devices and printers

Staff devices sit in one VLAN. Servers sit in another. Guest Wi-Fi has its own network. Printers, cameras and other connected devices may be grouped separately as well.

The next question matters more than the number of VLANs:

What is actually allowed to communicate between them?

In our broader business cybersecurity guide, we touched on segmentation as part of network security. Here, the focus is narrower: how those boundaries should reflect what users and devices actually need to reach.

Start With What Actually Needs to Communicate

Consider a typical office network.

Employees need access to business applications. Printers need to receive print jobs. Guest devices need internet access. Cameras or other connected devices may need to communicate with their own management systems.

They do not all need the same level of access.

A guest device may only require internet connectivity. A camera may need to communicate with its recorder but have no operational reason to connect to a finance workstation. An employee laptop may need access to one application server without needing access to every server on the network.

Instead of asking:

"How many VLANs do we have?"

Ask:

"Which connections between those VLANs are actually required?"

VLANs Create Logical Separation. Rules Define the Real Boundary.

Traffic between VLANs can still be permitted through routing, firewall rules or other access controls.

That means the useful part of segmentation is not the VLAN label itself, but the policy applied when traffic tries to move from one segment to another.

If a user VLAN needs to reach a particular application server, that communication can be allowed without automatically giving the same users access to unrelated systems.

The same principle applies to other segments: permit the communication required for the device or business function, rather than treating internal network access as unrestricted by default.

Guest Wi-Fi Makes the Logic Easy to See

Guest Wi-Fi is a straightforward example.

A visitor generally needs internet access. They do not need access to internal file shares, administrative interfaces or business servers.

The segmentation policy should reflect that purpose.

The same reasoning applies elsewhere. Device groups can be designed around their purpose and the resources they actually need to reach, rather than simply because they happen to operate inside the same organisation.

Printers, Cameras and IoT Devices Have Different Jobs

Shared and connected devices often perform narrow functions.

A printer needs to receive print jobs. A camera communicates with the systems needed for monitoring or recording. An IoT device may need access to a specific management platform.

Those requirements do not automatically justify broad access to the corporate network.

Network segmentation can limit each device group to the systems and services it actually needs.

The objective is not to create as many segments as possible. More segments also mean more policies to maintain.

Useful segmentation starts with understanding the communication requirement, then creating boundaries around it.

Segmentation Changes as the Network Changes

Network requirements do not stay fixed.

A new application may require an additional connection. A vendor may need temporary access. Troubleshooting may require a firewall rule to be widened. New devices may be added to an existing segment.

Those changes can all be legitimate.

The issue is whether the resulting rules still reflect the current requirement after the original change is complete.

A temporary exception, for example, may no longer be necessary once a project ends. An old application rule may remain even after the application has been retired.

Reviewing network segmentation therefore involves more than checking which VLANs exist. It also means checking whether the communication allowed between them still has a reason to be there.

A More Useful Way to Review Network Segmentation

For each segment, start with four questions:

What does this group need to reach?

What does it not need to reach?

Which rules currently allow that communication?

Are those rules still required today?

The goal is this: allow the communication the business needs, without leaving unnecessary paths between parts of the network that have no reason to communicate.

If you're reviewing your organisation's network segmentation and access control strategy, learn more about our Network Security Solutions.

 
 
Abstract Lines

STAY IN THE KNOW

Thanks for submitting!

Get started with RoyceMedia

Drop us a message and our team of experts will be in touch with you.

Our Location

211 Henderson Road #09-04

Singapore 159552

RoyceMedia official YouTube channel
RoyceMedia official LinkedIn page

Follow Us

RoyceMedia official Facebook page
IT and OT infrastructure and operational services

© Copyright by ROYCEMEDIA TECHNOLOGIES PTE LTD. All Rights Reserved.

Enterprise IT infrastructure and operations support
bottom of page