Type | Date

Enterprise Network Security

Practical network security for real enterprises: zones, east-west control, management plane isolation, and why sourcing is part of security.

Perimeter-only security failed years ago. Hybrid work, cloud adjacency, ransomware lateral movement, and fragile supply chains mean the network design itself is a control — not just a pipe for a single edge firewall.

1. Zone the network on purpose

Flat layer-2 domains maximize blast radius. Minimum viable zones for most enterprises:

Enforce with VRFs or at least discrete VLANs + gateway ACLs/firewall policy between zones. Micro-segmentation is a journey; start with coarse zones that match ownership and risk.

2. East-west is the fight

3. Protect the management plane

4. Edge and remote access

5. Supply chain is security

Counterfeit or tampered network hardware is a documented class of risk. Controls that matter:

6. Detection and response basics

7. Hardware choices that support the design

Security architecture fails when the box cannot enforce it — insufficient firewall throughput, missing segmentation features, or no spares for the choke-point appliance. Size for inspected throughput and HA pairs where the business requires continuous operation.

Nettech supplies new and refurbished security and switching platforms and can help map hardware to a zone design. Shop security & switching · Ask an engineer