Network Segmentation Visualizer
Design Secure Network Zones
Network Segmentation Design Lab
Place IoT, public, corporate, and management assets into zones, write least-privilege firewall rules, then simulate breach movement to see what the segmentation contains.
Goal
Contain breaches with zones, default-deny policy, and explicit service exceptions.
Try
Start with Flat Starter, run an attack, then switch to Recommended Segmentation.
Watch
Compare attack result, policy matrix, score rationale, and misplaced devices.
Reflect
Which one allowed path would an attacker reuse for lateral movement?
Guided Investigation
- Run Flat Starter and notice how default-allow policy makes lateral movement easy.
- Use Recommended Segmentation and inspect which traffic is allowed by exception.
- Add a risky IoT-to-Corporate allow rule and rerun the attack to see the containment break.
Scenario Focus
Flat Starter intentionally puts too many assets in one permissive trust area so students can see why segmentation is needed.
Device Placement
Firewall Policy
Attack Simulation
Security Snapshot
Score
--
Placed
--
Rules
--
Risk
--
?
Choose a preset or adjust placement and rules to see the segmentation score.
Event Log
Zone Map
Why This Score
The rationale updates when placement, policy, or rules change.
Attack Path Result
| Target | Decision | Reason |
|---|
Policy Matrix
| Path | Any Service | Useful Signal |
|---|
Segmentation Check
| Question | Current Signal | Why It Matters |
|---|