What is Network Segmentation?
Network segmentation divides a network into logical or physical zones and controls traffic between them. Boundaries can use subnets, VLANs, firewalls, cloud security controls, or software policy. Segmentation can limit reachability and lateral movement, but it does not make a segment trusted or stop every attack. Access between segments still needs explicit policy, monitoring, and application controls.
Why it matters
A flat network can let one compromised system reach many other systems. Segmentation narrows permitted communication and gives teams clear points where they can enforce and observe traffic policy.
How it works
- Group systems and data flows into zones based on function, sensitivity, and risk.
- Place enforcement controls between zones and allow only the required source, destination, protocol, and service flows.
- Monitor denied and allowed flows, test the boundaries, and update policy when systems or risks change.
Example
A developer workstation can reach a build dashboard through Pomerium, but firewall rules block a direct path from the workstation segment to the build database.
Pomerium boundary
Pomerium can narrow application access across network boundaries by applying identity and context policy to each protected route. Pomerium does not create VLANs, subnets, firewall zones, or packet-level network segments.
Limits and non-claims
- A segment is not trusted merely because its traffic crossed a boundary control.
- Shared services, unsafe exceptions, and configuration errors can create paths around the intended boundary.
- Network-level rules do not replace user authorization and input validation inside an allowed application.
Evaluation checklist
- Which boundary separates the systems, and which flows must cross it?
- Which identity and application authorization checks remain necessary after the network permits a flow?
- Can routing, shared services, management access, or failover bypass the segment boundary?
