Perimeter-only security failed years ago. Hybrid work, cloud adjacency, ransomware lateral movement, and fragile supply chains mean the network design itself is a control — not just a pipe for a single edge firewall.
1. Zone the network on purpose
Flat layer-2 domains maximize blast radius. Minimum viable zones for most enterprises:
- User / workplace
- Server / app
- Management / OOB
- Guest / BYOD
- OT / lab (if present) — aggressively isolated
Enforce with VRFs or at least discrete VLANs + gateway ACLs/firewall policy between zones. Micro-segmentation is a journey; start with coarse zones that match ownership and risk.
2. East-west is the fight
- Do not assume north-south firewalling catches modern attacks.
- Place inspection at zone boundaries where traffic must cross trust levels.
- Prefer identity-aware and application-aware policy over endless port objects when platforms allow it.
- Log allows and denies to a collector you actually watch.
3. Protect the management plane
- Out-of-band or tightly ACLed management network
- Jump hosts; no direct SSH from the open workplace VLAN to every switch
- MFA on administrative paths (IdP / VPN / PAM as fits your stack)
- Unique credentials; rotate on role change
- Disable unused services (telnet, http, legacy SNMP)
- Config backups encrypted and access-controlled — they contain secrets
4. Edge and remote access
- Terminate VPN on capacity-sized platforms with current software
- Split tunnel only with a written exception process
- Guest wireless: separate SSID, separate zone, rate-limit, no lateral path to servers
5. Supply chain is security
Counterfeit or tampered network hardware is a documented class of risk. Controls that matter:
- Buy from sellers who document provenance and testing
- Verify serials and cosmetics against expectations
- Validate software hashes/trains from trusted sources
- Stage and baseline configs yourself — do not run unknown startup-configs
- Wipe decommissioned gear before resale or disposal
6. Detection and response basics
- NetFlow/IPFIX or equivalent for east-west visibility
- Central syslog with retention that matches your IR needs
- Time sync everywhere (NTP) or your timelines will lie
- A one-page IR contact tree: who isolates a segment at 3 AM?
7. Hardware choices that support the design
Security architecture fails when the box cannot enforce it — insufficient firewall throughput, missing segmentation features, or no spares for the choke-point appliance. Size for inspected throughput and HA pairs where the business requires continuous operation.
Nettech supplies new and refurbished security and switching platforms and can help map hardware to a zone design. Shop security & switching · Ask an engineer