Avantec AG
Fully
Network Segmentation Without Network Reconstruction – IT Security
- 08 August 2026
- 100%
- Permanent position
- Fully
About the job
Without sufficient network segmentation, attackers often find it easy to move laterally within the network. Due to this vulnerability, cybercriminals can access crown jewels such as domain controllers, CRM, or ERP systems without much resistance once they are in the same network segment. I want to demonstrate how network segmentation can be implemented using a use case with Illumio.
To prevent the attacker’s lateral movement, it is essential for companies to segment their network. However, many shy away from the associated effort and additional costs. This often requires extensive changes in subnetting, routing, and IP addressing of systems.
Since traffic is controlled by the firewall, these changes significantly increase traffic, often pushing existing infrastructure to its limits. The firewall then needs to be replaced by a more powerful version or multiple firewalls to meet new requirements and handle the traffic.
Is there an alternative?
Illumio Core enables segmentation down to micro-segmentation of server and endpoint systems without making changes to the network or firewall infrastructure.
The product consists of two key components: the Policy Compute Engine (PCE) and the Virtual Enforcement Node (VEN). The PCE is the server side of the Illumio platform and is available either as SaaS or on-premises. It acts as a controller for policies and as a central manager for the VEN.
The VEN is the agent installed on systems (referred to as "workloads" in Illumio) and communicates with the PCE. Once the VEN is installed and activated (or "paired") on a system, it is called a "Managed Workload" because it can manage the native host firewall.
The Illumio PCE Web Console: MAP View
Systems can also be created in the PCE where no VEN can be installed, such as IoT devices or systems with unsupported operating systems. These are created as "Unmanaged Workloads." Since no VEN agent is installed on these hosts, the native host firewall cannot be managed. However, policies can be created from and to a "Managed Workload" because the policy is enforced on the VEN-installed system.
Illumio is primarily managed via a graphical web interface called the PCE Web Console. Additionally, it has a powerful REST API that allows common administrative tasks to be performed. This enables, for example, extensive workload groups to be managed automatically rather than handling each workload individually.
Can Illumio Core replace a network firewall?
Illumio does not have the comprehensive capabilities of a modern Next Generation Firewall (NGFW), which can analyse traffic with features like Intrusion Prevention System (IPS) or SSL inspection at a deeper level to detect and block threats.
The product focuses not on threat detection but on preventing the spread of threats. It utilises the native host firewall functions of a server’s operating system to implement network segmentation.
This means communication between applications and systems can be controlled at the smallest network unit. Unlike an NGFW, which operates at the network level, Illumio Core focuses on controlling communication at the application level.
Can’t I achieve the same as Illumio Core simply with a network firewall?
Of course, that is undoubtedly possible, but at what cost? For example, if micro-segmentation of servers in a DMZ is desired, this requires extensive adjustments to subnets and IP addressing. To control traffic through the firewall, new, separate small subnets must be set up for each server. Any move of a system from one zone to another requires a change of IP address.
Such changes can have significant impacts and involve a lot of effort to restructure the network. For example, applications that previously used a server’s IP address instead of the Fully Qualified Domain Name (FQDN) for communication may no longer work after the change. Therefore, such adjustments must be made with great caution. This leads to the implementation of a traditional zone concept usually being considered a long-term strategic project.
Label-based Policy Management
Furthermore, policies must be written for each new zone, in this case for individual server connections, to allow only legitimate traffic. This results in increasingly complex management and reduced clarity, as firewall rules multiply many times over.
With Illumio Core, as mentioned, nothing is changed in the network, subnets, or IP addressing. It can therefore be seamlessly integrated into the existing infrastructure.
Illumio Core uses a label-based policy model, meaning it does not use IP addresses or subnets when creating rules, unlike traditional firewall solutions. This allows workloads to be categorised and policies to be created more quickly. It is based on four labels: Role, Application, Environment, and Location. Additionally, any other dimensions, such as business unit, risk class, or other object data, can be attached to objects to allow granular filtering both on the map and in the policy.
Policies are mainly written from the application perspective, i.e., application-centric. The scope defines the area consisting of labels to which various applications’ workloads belong.
Workloads (systems) are defined with labels.
Viewing policy-based traffic in a map
Another advantage of Illumio is the many options to visualise traffic; one of these is the App Group "MAP," which shows traffic within, from, and to an application and even offers the possibility to create a rule directly from the map to allow a specific flow in the policy.
Representation of the Finance application (with Prod environment and CA location) in the App Group MAP
Conclusion
Illumio Core undoubtedly does not replace a firewall, especially not a perimeter firewall, and that is not its goal.
Nevertheless, it is a valuable addition for companies that have not yet implemented comprehensive network segmentation. A typical example would be companies with a traditional flat architecture, usually consisting of a DMZ, a server zone, and a client zone.
Another use case is companies that have long recognised the benefits of micro-segmentation but have been deterred by the perceived complexity of implementation with traditional methods.
Further strengths of Illumio Core lie in visibility, enabling companies to display network traffic in detail and quickly identify potential security risks. Additionally, Illumio Core offers a flexible and scalable solution that allows companies to gradually adapt and expand their security measures without compromising operational efficiency.
Introduction to Zero Trust – a paradigm shift
Knowing the risks of ChatGPT
Getting the best out of Check Point Firewalls: New features and optimisation options
Cyber Security Trends 2023 – the arms race continues
The article Network Segmentation Without Network Reconstruction first appeared on Tec-Bite.