Skip to content

Network Security Architecture

Network security architecture encompasses the design and implementation of controls at layers 1–4 to protect data in transit, limit lateral movement, and enforce access policy across the enterprise network.

In this section

PageWhat it covers
Physical & Layer 2 SecurityPort security, MAC filtering, STP hardening, physical access controls
VLANs & PVLANsVLAN design, trunk security, Private VLANs for host isolation
Layer 3 Attacks & MitigationIP spoofing, routing protocol attacks, uRPF, prefix filtering
Routers & FirewallsOn-premises and cloud firewall patterns, stateful inspection, ACLs
Macro, Micro & Identity SegmentationSegmentation tiers and identity-based policy
Network vs Access SegmentationComparing network-layer and access-layer control models
Web & SMTP Proxy SecurityExplicit and transparent proxies, TLS inspection, mail security
Layer 2 & 3 Benchmarks & AuditingCIS benchmarks, network auditing tools and techniques
Securing SNMP & NTPSNMPv3, NTP authentication, and management plane hardening
Bogon Filtering, Blackholes & DarknetsBogon prefix lists, RTBH, darknet monitoring

Released under the MIT Licence.