# Network Segmentation Without Stopping the Business

> An auditor or insurer told you to segment the network. How to run discovery, pick the first boundary, log before enforcing, and phase it without outages.

*Source: https://trybussolutions.com/network-segmentation-without-stopping-the-business/ · Trybus Solutions · Chattanooga, TN · 423-633-1817 · info@trybussolutions.com*

- [Home](https://trybussolutions.com/)
- Company[About us](https://trybussolutions.com/about-us/)
- [Careers](https://trybussolutions.com/careers/)
- Solutions[Collaboration](https://trybussolutions.com/collaboration-unified-communications/)
- [Networking & Connectivity Solutions](https://trybussolutions.com/networking-connectivity/)
- [Cybersecurity Solutions](https://trybussolutions.com/cybersecurity/)
- [Cloud & Infrastructure](https://trybussolutions.com/cloud-and-infrastructure/)
- [Governance, Risk & Compliance](https://trybussolutions.com/governance-risk-compliance/)
- [Digital Workplace](https://trybussolutions.com/digital-workplace/)
- Services[Implementation & Migration](https://trybussolutions.com/implementation-migration/)
- [Managed Services & Support](https://trybussolutions.com/managed-services-and-support/)
- [Trybus Connect](https://trybussolutions.com/trybus-connect/)
- Industries[Enterprise](https://trybussolutions.com/enterprise/)
- [Education](https://trybussolutions.com/education/)
- [Healthcare](https://trybussolutions.com/healthcare/)
- [Financial Services](https://trybussolutions.com/financial-services/)
- [Retail](https://trybussolutions.com/retail/)
- [Public Sector](https://trybussolutions.com/public-sector/)
- [Tribal Organization](https://trybussolutions.com/tribal-organization/)
- [Resources](https://trybussolutions.com/resources/)
- [Partners](https://trybussolutions.com/partners/)
- [Home](https://trybussolutions.com/)
- Company[About us](https://trybussolutions.com/about-us/)
- [Careers](https://trybussolutions.com/careers/)
- Solutions[Collaboration](https://trybussolutions.com/collaboration-unified-communications/)
- [Networking & Connectivity Solutions](https://trybussolutions.com/networking-connectivity/)
- [Cybersecurity Solutions](https://trybussolutions.com/cybersecurity/)
- [Cloud & Infrastructure](https://trybussolutions.com/cloud-and-infrastructure/)
- [Governance, Risk & Compliance](https://trybussolutions.com/governance-risk-compliance/)
- [Digital Workplace](https://trybussolutions.com/digital-workplace/)
- Services[Implementation & Migration](https://trybussolutions.com/implementation-migration/)
- [Managed Services & Support](https://trybussolutions.com/managed-services-and-support/)
- [Trybus Connect](https://trybussolutions.com/trybus-connect/)
- Industries[Enterprise](https://trybussolutions.com/enterprise/)
- [Education](https://trybussolutions.com/education/)
- [Healthcare](https://trybussolutions.com/healthcare/)
- [Financial Services](https://trybussolutions.com/financial-services/)
- [Retail](https://trybussolutions.com/retail/)
- [Public Sector](https://trybussolutions.com/public-sector/)
- [Tribal Organization](https://trybussolutions.com/tribal-organization/)
- [Resources](https://trybussolutions.com/resources/)
- [Partners](https://trybussolutions.com/partners/)
- [Home](https://trybussolutions.com/)
- [Company](https://trybussolutions.com/about-us/)[About us](https://trybussolutions.com/about-us/)
- [Careers](https://trybussolutions.com/careers/)
- Solutions[Collaboration & Unified Communications](https://trybussolutions.com/collaboration-unified-communications/)
- [Networking & Connectivity Solutions](https://trybussolutions.com/networking-connectivity/)
- [Cybersecurity Solutions](https://trybussolutions.com/cybersecurity/)
- [Managed Services & Support](https://trybussolutions.com/managed-services-and-support/)
- [Governance, Risk & Compliance Solutions](https://trybussolutions.com/governance-risk-compliance/)
- [Cloud & Infrastructure](https://trybussolutions.com/cloud-and-infrastructure/)
- [Digital Workplace](https://trybussolutions.com/digital-workplace/)
- Services[Implementation & Migration](https://trybussolutions.com/implementation-migration/)
- [Architecture & Solution Design](https://trybussolutions.com/architecture-solution-design/)
- [Trybus Connect](https://trybussolutions.com/trybus-connect/)
- [Trybus Hub](https://trybussolutions.com/trybus-hub/)
- Industries[Enterprise](https://trybussolutions.com/enterprise/)
- [Education](https://trybussolutions.com/education/)
- [Healthcare](https://trybussolutions.com/healthcare/)
- [Financial Services](https://trybussolutions.com/financial-services/)
- [Retail](https://trybussolutions.com/retail/)
- [Public Sector](https://trybussolutions.com/public-sector/)
- [Tribal Organization](https://trybussolutions.com/tribal-organization/)
- [Partners](https://trybussolutions.com/partners/)
- [Resources](https://trybussolutions.com/resources/)
- [Shop](https://shop.trybussolutions.com/)
- [Contact Us](https://trybussolutions.com/contact-us/)
- [Customer Portal](https://trybussolutions.myportallogin.com)
- [Home](https://trybussolutions.com/)
- [Resources](https://trybussolutions.com/resources/)
- Network Segmentation Without Stopping the Business

# Network Segmentation Without Stopping the Business

July 24, 202610 min readSecurity

## Why the Network Is Still Flat

Very few flat networks were designed that way. They were built one decision at a time by people solving the problem in front of them. A building was fitted out and everything went on one VLAN because that is what the switches shipped with. A network with no boundaries in its design never says no.

The instruction to change that arrives from outside: an auditor writes a finding with a date attached, an insurer asks about lateral movement, or a customer's security review asks how their data is separated. The PCI Security Standards Council is direct about the stakes: segmentation is not itself a PCI DSS requirement, but "without adequate network segmentation (sometimes called a 'flat network') the entire network is in scope of the PCI DSS assessment."

Projects stall when they are scoped as one program across the whole estate. NIST makes a similar point about zero trust: the transition "is a journey concerning how an organization evaluates risk in its mission and cannot simply be accomplished with a wholesale replacement of technology." An estate gets segmented in pieces, and the first piece has to be small enough to finish.

## Find Out What Actually Talks to What

You cannot write a policy for traffic you have never seen. Every segmentation project reaches a meeting where somebody asks whether the imaging server needs to reach the domain controllers on an undocumented port, and nobody has looked. Most of the answer is already sitting in data you own:

Give discovery a fixed length, then be honest about what it missed. Two to four weeks of flow data covers the weekly patterns and none of the monthly ones. Month end, payroll, imaging weekends and the annual audit extract fall outside it. Write down what you did not observe, because that list is what the first enforcement window will find.

- **Flow records and the logs you already have** NetFlow, sFlow or IPFIX from the routers and core switches, plus the logs from firewalls already sitting at the edges, give you conversations, ports and volumes.
- **Address and switch data** Reservations, static assignments, MAC address tables and LLDP neighbors tie an address to a port, a closet and a building, which is how undocumented devices get found.
- **A passive sensor where traffic never crosses a router** Flow data only sees what is routed. On a flat VLAN the interesting traffic never leaves the broadcast domain, so a SPAN port feeding a passive sensor is the only way to see it.
- **The people who own the equipment** Facilities, physical security, biomedical engineering and plant engineering know which vendor dials in and what stops working when a link drops.

## The Devices That Cannot Move and Cannot Take an Agent

Every environment has equipment that will not cooperate. Building management controllers and boiler panels. Cameras, badge readers and door controllers. Nurse call systems, infusion pumps and lab analyzers. Programmable controllers and historians on the plant floor. The machine in the corner running an unsupported operating system.

This equipment shares properties that make the usual playbook useless. Protection software cannot be installed on it. The maintenance contract often states that modifying the host voids support. And some of it will not survive being scanned. Cisco's industrial automation security design guide explains why legacy control devices are fragile under a centralized scan: "the processing of the barrage of ARP requests can overwhelm the networking stack on legacy IACS devices causing them to crash."

So discovery on those ranges stays passive, and the control is a boundary around the device rather than software on it: an access policy at the nearest enforcement point, a defined path for the vendor who supports it, and a written exception where traffic has to stay open. In healthcare this is acute, because biomedical engineering owns devices that IT is expected to protect and is not permitted to touch.

## Start at One Boundary That Matters

The useful question early on is which single boundary, drawn once, removes the most exposure for the least disruption. Dividing the whole estate is a later question, and answering it first produces a two-year program with nothing enforced at the end.

The candidates are usually the same. Building and operational systems carry high risk and few legitimate flows, which makes that boundary tractable. A boundary between users and server or management interfaces stops a compromised laptop from reaching a hypervisor console. A boundary around whatever sits in an audit scope turns an open finding into a closed one, and it is the easiest to fund.

- **It has one owner** Somebody who can approve an exception the same day, rather than a committee that meets monthly.
- **The device population is stable** A controller estate that changes twice a year beats the user VLAN where a laptop appears every hour.
- **The legitimate traffic is narrow** A twenty-rule policy can be reasoned about by one engineer. A four-hundred-rule policy accumulates exceptions faster than it removes risk.
- **Failure is loud** You want to know within minutes, rather than at quarter close when a batch job has been failing silently.

## Every Policy Goes Into Logging Before It Enforces

No segmentation policy should enforce on the day it is written. Between design and enforcement there is a stage where the policy records traffic while permitting everything, and the major platforms support it.

For wired access control, Cisco documents monitor mode for exactly this: authentication runs across the infrastructure while authorization is left open, so that "irrespective of the endpoint's authentication status (success or failure), the port is always open." You get the list of devices that would have failed, and where they are plugged in, before anything is denied. On the firewall, Cisco's Secure Firewall Management Center offers a Monitor rule action that "forces connection logging regardless of how matching traffic is eventually handled" without permitting or denying it. The inverse is worth knowing as well: on Palo Alto Networks firewalls the predefined interzone-default rule denies traffic between zones and writes no log until you override it and enable logging, so a new zone can drop traffic that never appears in the log viewer.

Run the logging stage across a monthly boundary, then work the list. Every unanticipated flow is a legitimate dependency, a device in the wrong place, or something that should have been decommissioned years ago.

## What Breaks, and How to Test for It First

The failures a segmentation project produces are predictable, which means they can be proven in a pilot subnet before the change window instead of discovered during it.

- **Printers and anything discovered by multicast** Multicast DNS is link-local by definition. RFC 6762 states that any name ending in ".local." "is link-local, and names within this domain are meaningful only on the link where they originate." Move a workstation into a new subnet and the printer it found by itself disappears. A print server or direct IP queues resolves it, and that choice belongs in the design.
- **Imaging and PXE boot** Microsoft's guidance for booting from a PXE server on another network is to configure the routers to forward the client request to the PXE server "just like you do with the DHCP server." A new subnet without that IP helper entry images nothing.
- **Legacy applications** Hard-coded addresses in configuration files, dynamic high port ranges negotiated at runtime, and servers that open connections back toward the client. These have to be tested rather than researched, because their documentation assumes a flat network.
- **Backup, management and monitoring paths** Backup agents, array replication, hypervisor management, out-of-band console access and your own SNMP and syslog collection cross the boundaries you are closing. Wake-on-LAN needs its own check: a magic packet is a broadcast.

## Phasing It So the Business Keeps Running

A phase that keeps the business running has the same shape every time, and it repeats per boundary. Discovery on the target boundary. Design reviewed with the owner of the systems inside it, not only with IT. Policy deployed in logging. Enforcement in a change window with a rollback that has been written down and timed. Then a bed-in period before the next boundary starts.

Discovery will change the scope. That is what it is for. A boundary turns out to have four vendor paths instead of one, the controller estate shares a VLAN with payroll, or the segmentation an auditor asked for exposes the network design underneath it. The honest sequence then is a conversation about what changed, a price and a schedule attached, and a decision that belongs to the customer.

Trybus Solutions runs this as segmentation and secure access work, alongside the evidence a governance, risk and compliance program has to produce. Some engagements are architecture and design only, and the customer's own team builds against the documentation. Others run through to implementation and migration with our engineers in the change windows. Either way: find out what talks to what, pick the boundary that matters, log before you enforce, and move one piece at a time.

## Common questions

### How long does a network segmentation project take?

Discovery on a defined boundary usually runs two to six weeks, because it has to cross at least one monthly cycle to be worth anything. Taking that first boundary from design through logging to enforcement typically adds another one to two months, most of which is waiting for change windows rather than engineering. The whole estate is a program measured in quarters. Anyone quoting a duration before discovery has finished is guessing, and that includes us.

### Do we need microsegmentation, or are VLANs and firewalls enough?

For most mid-market estates, VLANs with a real enforcement point between them, plus access control at the switch port, close the exposure an auditor or an insurer is asking about. Microsegmentation down to the individual workload earns its keep where the workloads already sit in a platform that supports it and where somebody owns the policy long term. Buying it for a flat network with no discovery behind it produces an expensive tool that nobody can operate.

### Our auditor told us to segment. Does that mean the whole network?

Usually not. Most findings concern a specific scope: a cardholder data environment, a set of regulated systems, or a class of device. Segmentation is not itself a PCI DSS requirement, for example, but a flat network places the entire network in scope of the assessment, which is what makes it expensive. Reducing the scope of the assessment is often the cheaper objective, and it is worth confirming in writing with your assessor before a design is drawn.

### What do we do about devices that cannot take an agent?

They get a boundary instead. Discovery on those ranges stays passive because active scanning can knock older controllers over, the control is an access policy at the nearest enforcement point, and the vendor support path is defined and restricted rather than left open. The person who owns that equipment, who is frequently not in IT, has to be part of the design and the testing.

### Can you work on a network somebody else designed?

Yes, and most of this work is on networks somebody else built. We start by reading the live configuration and the actual traffic rather than the documentation, because after a few years the two rarely agree. If the existing design is sound we will say so and work within it.

## Sources

- [PCI Security Standards Council — Guidance for PCI DSS Scoping and Network Segmentation](https://listings.pcisecuritystandards.org/documents/Guidance-PCI-DSS-Scoping-and-Segmentation_v1_1.pdf)
- [NIST SP 800-207 — Zero Trust Architecture](https://csrc.nist.gov/pubs/sp/800/207/final)
- [Cisco — Industrial Automation Security Design Guide: Gain Asset Visibility and Device Posture](https://www.cisco.com/c/en/us/td/docs/Technology/industrial-automation-security-design-guide/m-gain-asset-visibility-and-device-posture.html)
- [Cisco — ISE Secure Wired Access Prescriptive Deployment Guide (Monitor Mode)](https://community.cisco.com/t5/security-knowledge-base/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515)
- [Cisco — Secure Firewall Management Center Device Configuration Guide: Access Control Rules](https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/740/management-center-device-config-74/access-rules.html)
- [Palo Alto Networks — Enable Logging for Traffic That Does Not Match Any Rules](https://docs.paloaltonetworks.com/best-practices/internet-gateway-best-practices/best-practice-internet-gateway-security-policy/define-the-initial-internet-gateway-security-policy/step-5-enable-logging-for-traffic-that-doesnt-match-any-rules)
- [RFC 6762 — Multicast DNS](https://www.rfc-editor.org/rfc/rfc6762)
- [Microsoft Learn — Boot from a PXE server on a different network](https://learn.microsoft.com/en-us/troubleshoot/mem/configmgr/os-deployment/boot-from-pxe-server)

## Keep reading

- [WirelessWireless Site Surveys and What Predictive Design Misses10 min read](https://trybussolutions.com/wireless-site-survey-predictive-design/)
- [NetworkingWhat a Network Refresh Actually Involves9 min read](https://trybussolutions.com/what-a-network-refresh-involves/)
- [Contact CenterContact Center Migration: What to Scope First9 min read](https://trybussolutions.com/what-to-scope-before-choosing-a-contact-center/)

## Segment the boundary that matters first

Trybus Solutions maps what actually talks to what, writes the policy in logging mode, and enforces it in stages so the business keeps running.

Or call [423-633-1817](tel:+14236331817) · [info@trybussolutions.com](mailto:info@trybussolutions.com)
