Network Segmentation Visualizer
Network Segmentation Visualizer
Design Secure Network Zones
Network Segmentation Design Lab
Place IoT, public, corporate, and management assets into zones, write least-privilege firewall rules, then simulate breach movement to see what the segmentation contains.
Try
Start with Flat Starter and Default Policy set to Default Allow, then press Play Attack before applying Recommended Rules.
Observe
The attack result changes from allowed to blocked when an ordered deny rule covers its Source Zone, Destination Zone, and Service.
Explain
Default Policy containment follows source, destination, service, and the first applicable allow or deny rule.
Technical boundaries. The attack path uses deterministic zones and ordered allow or deny rules. It does not emulate a firewall, inspect payloads, model NAT, identity-aware policy, lateral movement exploits, rule-shadowing at scale, stateful sessions, or vulnerability severity.
Goal
Contain breaches with zones, default-deny policy, and explicit service exceptions.
Try
Start with Flat Starter, press Play Attack once, then switch to Recommended Segmentation.
Watch
Compare attack result, policy matrix, score rationale, and misplaced devices.
Reflect
Which one allowed path would an attacker reuse for lateral movement?
Guided Investigation
- Run Flat Starter and notice how default-allow policy makes lateral movement easy.
- Use Recommended Segmentation and inspect which traffic is allowed by exception.
- Add a risky IoT-to-Corporate allow rule and rerun the attack to see the containment break.
Scenario Focus
Flat Starter intentionally puts too many assets in one permissive trust area so students can see why segmentation is needed.
Device Placement
Firewall Policy
Attack Simulation
Security Snapshot
Score
--
Placed
--
Rules
--
Risk
--
?
Choose a preset or adjust placement and rules to see the segmentation score.
Event Log
Zone Map
Why This Score
The rationale updates when placement, policy, or rules change.
Attack Path Result
| Target | Decision | Reason |
|---|
Policy Matrix
| Path | Any Service | Useful Signal |
|---|
Segmentation Check
| Question | Current Signal | Why It Matters |
|---|