Network Segmentation
Also known as: VLAN · Network Segregation
Network segmentation splits a company network into separate zones so a problem in one zone can't spread into the others.
Network segmentation divides a single connected network into several smaller, technically separated zones, usually using VLANs under the IEEE 802.1Q standard. Without segmentation, every device on the network can in principle see every other device on that same network. The point is to keep areas with different protection needs apart from each other, such as the office, the production floor and guest Wi-Fi.
In practice, each zone gets its own VLAN, and a firewall or managed switch only allows the connections between zones that are actually needed. In an office, one shared network for workstations, printers and Wi-Fi is usually fine. On a production floor the consequences of sharing one network are far bigger: an infected office laptop's file share must not be able to reach the same broadcast domain as a machine's control system.
A common mistake is planning segmentation only on paper without actually enforcing the rules between segments in the firewall or switch – the VLANs exist, but every connection between them is still open. It's just as common for a new device to end up on the wrong VLAN because a network port was never clearly assigned.
What it means in practice
In many SMEs, the office network, guest Wi-Fi and machine controllers still sit on the same network because it grew over time and was never planned. This usually shows up as a laptop in the office sharing the same IP address range as a production machine. NDVDL plans network segmentation for businesses where office, production and guest access have not yet been separated.
Is this handled properly at your site?
We look at how it actually stands with you — and say honestly whether anything needs doing.
Related terms
All termsA term from your quote missing here?
Send us the passage you do not follow. We will explain it — with no obligation to order anything.