About this interactive
Segmentation divides the network so that resources are separated by role, department or kind of device. Someone in administration does not automatically reach operations' servers, and a compromised machine in one segment cannot simply reach the others.
The lesson's segments:
- The screened subnet, also called the DMZ (demilitarized zone): a separate network for the servers the public must reach, such as the web servers. Firewall rules let outside users in to those servers. If the servers sat on the internal network and were compromised, the attacker would be inside; in the screened subnet, the internal network is still protected.
- Segments by department or role: administration, operations and sales each with their own servers, data and access.
- A management network: the switches, servers and database servers all need managing, and SNMP monitoring traffic runs there too. Only the people who manage the equipment can reach it, so others cannot see or reach the back ends.
- IoT, OT and embedded systems: smart thermostats and appliances (Internet of Things), robots and assembly lines (operational technology), and devices with a computer built in (embedded systems). They are often not updated and hard to see into, so they get their own segment, even on many home networks.
How it is built: before VLANs, every segment needed its own switch. A VLAN (virtual LAN) splits one switch into several separate LANs, port by port. Traffic between VLANs has to pass through a router or firewall, which is where it can be controlled. Micro-segmentation takes the idea further, into very small segments, so traffic can be controlled closely.
About TechKnowSurge
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →