Skip to main content

Perimeter

A security perimeter is a boundary where controls inspect or restrict communication. NIST zero trust does not remove firewalls or all network boundaries.

What is Perimeter?

A security perimeter is a boundary where controls inspect or restrict communication. NIST zero trust does not remove firewalls or all network boundaries. It removes implicit trust based only on network location or asset ownership and focuses policy on each resource request. Perimeter controls remain useful as defense in depth, but being inside a perimeter is not sufficient proof of trust.

Why it matters

A perimeter gives an organization a place to apply common controls to boundary-crossing traffic. Zero trust keeps that control as one layer while it removes automatic trust for users and devices inside the boundary.

How it works

  1. Define a boundary around an environment, network, application, or data set.
  2. Route relevant traffic through controls that can restrict, inspect, and log boundary crossings.
  3. Apply resource-level identity and context policy even after traffic passes the perimeter control.

Example

A firewall limits inbound VPC traffic, while Pomerium still verifies the user and route policy before it forwards a request to an internal administration site.

Pomerium boundary

Pomerium sits between users and protected services. It authenticates the user through an identity provider and evaluates configurable policy before it routes a request. This adds resource-focused enforcement that does not rely only on network location.

Limits and non-claims

  • Cloud services, remote users, and nested environments make one fixed perimeter incomplete.
  • A direct path, stolen internal credential, or compromised internal system can bypass location-based trust assumptions.
  • Perimeter enforcement does not replace secure endpoints, application controls, or data protection.

Evaluation checklist

  • Which assets and flows does the selected perimeter actually separate?
  • Does any policy treat an inside location as proof of identity or permission?
  • Which cloud, remote, partner, management, or control-plane path crosses another boundary?

Sources and further reading

Keep learning

Network and Infrastructure

Firewall

A firewall is a device or program that controls network traffic between networks or hosts according to a firewall policy.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo