Skip to content
CoRISE

From VLANs to Enforcement: Inspecting East-West Traffic

Assess segmentation through enforced paths and policies, not segment names.

1 min read
  • security
  • infrastructure
  • reliability
Open table of contents

Conclusion

Assess segmentation through enforced paths and policies, not segment names.

Context

Separate VLANs still leave routed and same-segment communication. Examine the actual inspection point traversed by each traffic path.

Design and verification scope

Assess the following responsibilities and boundaries when designing and verifying a configuration.

  • Routing
  • Firewall chokepoints
  • Policy
  • Inspection
  • Lateral movement
  • Bypasses
  • Operational cost

Decision rationale

Use the relationship between Routing and Operational cost to compare the responsibilities of the selected approach and alternatives. Separate retained constraints from what the new boundary can change.

Trade-offs

Compare the implementation, maintenance and review work introduced by Firewall chokepoints with the control it provides. Include failure paths, operator effort and conditions in which the approach should not be adopted.

Limitations

Review L2/L3 topology, allow lists, packet records and failover paths, including same-VLAN and encrypted-traffic limitations.

These cases provide attributed design context. They do not establish that the proposed experiments or configurations were delivered in those engagements.

Contact

Tell us about your engineering challenge.

Talk with CoRISE about the design, implementation and operation of your systems.

Start a Conversation