Segmentation design and strategy should be based on the critical asset value or resource, not simply on network boundaries-based isolation. This design strategy should start as a high level network design which segregates the various zones through traditional network boundaries such as DMZ, data center, virtual cloud and campus network. It then consistently drills into each zone to provide isolation between the applications within it:
Virtual LAN (VLAN): A flat local area network segment forms a single broadcast domain. This means that if a user broadcasts information on a LAN, the broadcast will be heard by all ...