Network Segmentation Visualizer

Network Segmentation Visualizer

Design Secure Network Zones

Network Segmentation Design Lab

Place IoT, public, corporate, and management assets into zones, write least-privilege firewall rules, then simulate breach movement to see what the segmentation contains.

Try
Start with Flat Starter and Default Policy set to Default Allow, then press Play Attack before applying Recommended Rules.
Observe
The attack result changes from allowed to blocked when an ordered deny rule covers its Source Zone, Destination Zone, and Service.
Explain
Default Policy containment follows source, destination, service, and the first applicable allow or deny rule.
Goal
Contain breaches with zones, default-deny policy, and explicit service exceptions.
Try
Start with Flat Starter, press Play Attack once, then switch to Recommended Segmentation.
Watch
Compare attack result, policy matrix, score rationale, and misplaced devices.
Reflect
Which one allowed path would an attacker reuse for lateral movement?

Guided Investigation

  1. Run Flat Starter and notice how default-allow policy makes lateral movement easy.
  2. Use Recommended Segmentation and inspect which traffic is allowed by exception.
  3. Add a risky IoT-to-Corporate allow rule and rerun the attack to see the containment break.

Scenario Focus

Flat Starter intentionally puts too many assets in one permissive trust area so students can see why segmentation is needed.

Quick Presets
Ready: Flat Starter loaded

Device Placement

Firewall Policy

Attack Simulation

Security Snapshot

Score
--
Placed
--
Rules
--
Risk
--
?
Choose a preset or adjust placement and rules to see the segmentation score.

Event Log

Zone Map

Why This Score

The rationale updates when placement, policy, or rules change.

    Attack Path Result

    Target Decision Reason

    Policy Matrix

    Path Any Service Useful Signal

    Segmentation Check

    Question Current Signal Why It Matters