Separating traffic.
WHY IT MATTERS
Flat networks allow anything to reach anything, so one compromise reaches everything.
WHAT TO SEPARATE
Customer traffic from management Storage from general traffic Each customer from every other Backup traffic Out-of-band management
WHAT VIRTUAL LANS PROVIDE
Logical separation over shared physical infrastructure.
WHAT THEY DO NOT PROVIDE
Security, by themselves.
WHY
Misconfiguration bridges them, and traffic between them passes through routing you must control.
WHAT TO ENFORCE AT THE BOUNDARY
Filtering, denying by default.
WHAT OVERLAY NETWORKS PROVIDE
Logical networks independent of the physical topology.
WHAT THEY SUIT
Multi-tenant environments where each customer needs isolation.
WHAT MICROSEGMENTATION IS
Policy applied per workload rather than per network segment.
WHAT IT PROVIDES
Containment, even between machines on the same segment.
WHAT TO DOCUMENT
Every segment, what it contains, and what may cross between.
WHAT TO AUDIT
Whether the rules match the documentation.
WHAT YOU WILL FIND
Rules added for a temporary purpose, never removed.