Why split the network?
On a flat network, any device can reach any other. A virus on an office PC, a misconfigured camera or a broadcast storm can reach the machines on the production floor, and nothing stands in the way.
Production, the office and the cameras need different things. Production has to stay up and responsive, the office needs its everyday applications and the ERP, and the cameras only need to reach their recorder. Giving each its own zone keeps the access rules simple and the traffic easy to read, and it lets the ERP go first when the network is busy. Before the change, ERP slowdowns at busy times had been holding up production scheduling.
The three zones
Production zone
The machines and services the factory runs on. They get the tightest rules and the highest priority, and each service can reach only what it needs.
Office zone
Staff computers and the everyday office services. They work as before, but they can no longer reach production equipment directly.
CCTV zone
The cameras and their recorder sit on their own. Cameras are small embedded devices that rarely get updates, so they are kept well away from everything else. I designed and installed the camera system itself, too.
What sits between the zones
- Firewall: every connection between zones passes through it, and anything not allowed is dropped.
- Intrusion detection: watches the traffic crossing between zones and flags anything that looks wrong.
- Encrypted DNS: lookups go out over DoH or DoT, so they can’t be read or changed on the way.
- Quality of service: ERP and production traffic go first when the line is busy.
If a control doesn’t have a clear reason to exist and a way to check that it still works, it doesn’t stay.
How I make changes
I start from the traffic that is really there, not from a tidy diagram. I work out what has to talk to what, block the rest, make the smallest change that moves things forward, and then check both sides: the paths that should work still do, and the ones I blocked stay blocked.
If the new layout is harder to run than the old one, I haven’t finished.
Work with me
I look after routing, segmentation, DNS security, servers, backups, and the services people use on top of them. If you have that kind of role, I’d like to hear about it.
Get in touch