Network Segmentation Visualizer

Design Secure Network Zones

Network Segmentation Design Lab

Place IoT, public, corporate, and management assets into zones, write least-privilege firewall rules, then simulate breach movement to see what the segmentation contains.

Goal
Contain breaches with zones, default-deny policy, and explicit service exceptions.
Try
Start with Flat Starter, run an attack, then switch to Recommended Segmentation.
Watch
Compare attack result, policy matrix, score rationale, and misplaced devices.
Reflect
Which one allowed path would an attacker reuse for lateral movement?

Guided Investigation

  1. Run Flat Starter and notice how default-allow policy makes lateral movement easy.
  2. Use Recommended Segmentation and inspect which traffic is allowed by exception.
  3. Add a risky IoT-to-Corporate allow rule and rerun the attack to see the containment break.

Scenario Focus

Flat Starter intentionally puts too many assets in one permissive trust area so students can see why segmentation is needed.

Quick Presets
Ready: Flat Starter loaded

Device Placement

Firewall Policy

Attack Simulation

Security Snapshot

Score
--
Placed
--
Rules
--
Risk
--
?
Choose a preset or adjust placement and rules to see the segmentation score.

Event Log

Zone Map

Why This Score

The rationale updates when placement, policy, or rules change.

    Attack Path Result

    Target Decision Reason

    Policy Matrix

    Path Any Service Useful Signal

    Segmentation Check

    Question Current Signal Why It Matters