Department-based VLANs are easy to explain, but departments are not security boundaries.

Finance laptops, printers, cameras, conference-room systems, access control, build agents, servers, and network management have different risks even when the same team uses them. Placing them together because they share an org chart preserves unnecessary trust.

Segmentation should follow exposure and impact.

Classify The Workload

Evaluate each device or service by who manages it, what data it reaches, how exposed it is, how quickly it can be patched, and what happens if it is compromised.

Guest devices, unmanaged endpoints, building systems, cameras, production servers, backup infrastructure, and administrative interfaces should not share the same assumptions.

Risk classification creates boundaries that survive reorganizations.

Control Traffic Between Zones

A VLAN without enforced policy is mostly an organizational label.

Define which source may reach which destination, on which protocol, for what purpose. Deny unnecessary east-west traffic. Route sensitive paths through controls that can authenticate, inspect, log, and rate-limit where appropriate.

Keep management planes separate from ordinary user traffic.

Protect Shared Services

DNS, identity, logging, printing, update systems, and monitoring often connect many zones.

Treat them as explicit brokered services rather than reasons to flatten the network. Limit their inbound and outbound paths. Protect administrative interfaces separately from client-facing functions.

Shared does not need to mean universally reachable.

Verify The Boundary

Test segmentation from each zone.

Confirm allowed workflows, blocked paths, failover behavior, logging, IPv6 policy, wireless isolation, and temporary exceptions. Review firewall rules for unused objects and broad service groups. Compare intended policy with observed flows.

Run The Defense Test

Identify what each zone trusts. Control how devices enter and leave it. Use policy to contain compromise. Preserve flow and change evidence. Maintain safe administrative and recovery paths outside the affected segment.

Good segmentation does not eliminate connectivity. It makes every important connection intentional.