5 Network Security
Learn how network boundaries, secure protocols, traffic rules, segmentation, and ongoing operations work together to protect systems and data.
Network boundaries and access
Network security protects systems and data as they communicate. Data travels in packets: routers forward packets between networks, while switches connect devices within a local network. Protocols define how data is addressed, transported, and interpreted. IP provides addressing and routing; TCP and UDP carry application traffic. These basic protocols do not, by themselves, encrypt or authenticate communications.
Security controls can be placed at the network perimeter, between internal zones, on individual devices, and within applications. A perimeter remains useful, but users, devices, and services may connect from outside a traditional office network. A therefore evaluates access to particular resources rather than assuming that everything inside the network is trustworthy.
The central design question is not simply whether traffic is inside or outside the network: it is which systems need to communicate, and under what conditions.
Secure protocols and their limits
Protocols protect communication in different ways and at different layers:
HTTPS is HTTP carried over . When correctly configured and when the client validates the server’s certificate, TLS can provide confidentiality, integrity, and server authentication.
SSH provides an encrypted, authenticated channel commonly used for remote administration and secure file transfer. Administrators should verify host keys and carefully manage strong authentication.
IPsec protects IP traffic at the network layer. It can secure traffic between hosts, between security gateways, or between a host and a gateway, and is commonly used in VPNs.
DNS translates names into network information. Traditional DNS queries are not encrypted, so an on-path observer may see or interfere with them. DNS over TLS (DoT) and DNS over HTTPS (DoH) encrypt the exchange between a client and resolver, but do not hide all network metadata or guarantee that a requested destination is safe.
SNMPv3 supports authentication and encryption options for network management. Older or improperly configured management protocols can expose device information or credentials.
Encryption protects data in transit; it does not secure a compromised endpoint, make an untrusted recipient trustworthy, or replace access control. Secure systems validate certificates or host identities, use supported cryptographic settings, and maintain software and keys.
rules and traffic control
A controls network traffic between hosts or networks with different security requirements. Depending on its type, it may filter addresses and ports, track connection state, or inspect application-level traffic. Firewalls may be network appliances, cloud controls, or software on an individual host.
A useful policy permits only traffic required for a defined purpose and denies other traffic. For example, a public web server may accept HTTPS from the Internet, while its database accepts connections only from that web server—not directly from public networks. Rules should specify the source, destination, service, and direction.
Administrators should document, review, and test rules; remove obsolete exceptions; and monitor relevant allowed and denied traffic. A is important, but it does not replace patching, endpoint security, or application-level authorization.
Segmentation and controlled zones
divides a network into separate zones so devices and services do not all share unrestricted connectivity. Segments can be physical or logical, such as separate subnets or virtual LANs (VLANs). Firewalls, router access-control lists, or other policy controls govern communication between them. A VLAN alone is not a complete security boundary if routing between VLANs is unrestricted.
A holds services that must be reachable from less-trusted networks, such as public-facing web or mail servers. For example, Internet users may reach a web server in the DMZ, while that server may connect to a back-end service through a narrowly defined rule. Internet users are not granted direct access to the back-end network.
Segmentation limits : when one device is compromised, restrictive boundaries leave an attacker with fewer paths to reach other systems. Organizations can separate user devices, servers, management interfaces, guest Wi-Fi, and operational technology according to their needs and risks. Segmentation works best when rules are restrictive, boundaries are monitored, and network diagrams and policies remain current.
Operational defense and key takeaways
Effective network defense combines thoughtful design with ongoing operational practices:
Map systems and data flows. Identify which devices and services communicate, including cloud and remote-access connections.
Restrict exposure. Disable unnecessary services and management interfaces; do not expose device administration directly to the Internet.
Apply least-privilege traffic rules. Permit only necessary communication between zones and review exceptions regularly.
Secure remote access. Use approved VPN or other protected access methods, strong authentication, and limited permissions.
Maintain devices. Apply security updates, use secure configurations, and protect device credentials and management access.
Monitor and prepare. Centralize useful logs, watch for unexpected traffic or configuration changes, and maintain an incident-response plan.
Together, these measures support . If one control fails, other controls can help detect an intrusion or limit its impact. The practical takeaway is to combine traffic controls and protected communication with maintenance, monitoring, and restricted access.