Goal
Map trusted and untrusted network paths for a small environment.
Estimated cost: Free when performed with local diagrams, exports, or test data. If you use a real cloud, lab, or SaaS environment, verify cost and authorization first.
Concepts Reinforced
- segmentation
- management plane
- firewall zones
Prerequisites
- A non-production lab, diagram, or exported sample data.
- Authorization to review the data or configuration.
- A text editor or spreadsheet for notes.
Exact Steps
- Draw user, server, management, guest, and IoT segments.
- List allowed flows between segments.
- Mark any path to management interfaces.
- Define one deny rule and one monitoring point for each risky path.
Verification
No untrusted segment can reach management interfaces without an explicit controlled path.
Cleanup
Remove any temporary diagrams that include sensitive IP ranges.