A clean architecture drawing can coexist with broad firewall objects, stale vendor VPNs, dual-homed engineering hosts, unmanaged wireless bridges, or routes that bypass the stated boundary. Network segmentation validation compares the documented model with paths that exist under current configuration and operations.

Start with legitimate flows

List each required crossing by source, destination, protocol, direction, account, business owner, schedule, process purpose, and failure consequence. This makes broad or unexplained rules visible. It also prevents a security team from breaking a process simply because a flow was missing from the diagram.

Use more than one evidence source

Review firewall and router configurations, network-address translation, route tables, identity systems, remote-access gateways, jump hosts, switch state, passive traffic, DNS, and selected reachability tests. A blocked ICMP echo does not establish isolation. Validation should reflect the services and trust relationships an adversary or misconfigured asset could use.

  • Enterprise-to-DMZ and DMZ-to-operations boundaries.
  • Cell, area, safety, management, and vendor zones.
  • Jump-host controls, MFA, approvals, session recording, and time limits.
  • Dual-homed systems, modems, wireless paths, and temporary access.
  • Post-change testing against the original path.

Plan changes with the operator

Every recommendation should state the required process communication, affected owner, proposed control, safety and environmental dependencies, maintenance window, rollback condition, and expected risk reduction. Life safety, environmental protection, and stable operation take priority. Active testing requires operator-designated authority, an approved process condition, explicit stop points, process-risk review, and personnel able to halt the work. Some environments should remain limited to configuration and passive evidence.

Primary and public sources