The Flat Network Is the Last Unsegmented Zone in the Enterprise

Zero Trust reached the WAN edge but rarely the campus. See why VLANs and NAC fall short, and how Versa Secure SD-LAN enforces microsegmentation at the LAN edge.

Summary

Zero Trust programs have largely completed two phases, remote access and the WAN edge, while the physical campus network remains outside continuous identity-based validation. This post examines why flat and coarsely segmented LANs persist, why VLANs and port authentication do not constitute a segmentation strategy, and how Versa Secure SD-LAN makes segmentation a property of the fabric by enforcing Zero Trust and microsegmentation at the LAN edge.

  • Most Zero Trust programs have addressed remote access and the WAN edge while leaving the physical campus network outside continuous, identity-based validation.
  • VLANs and port-based authentication establish reachability boundaries and a one-time admission decision, which is a different thing from continuous least-privilege enforcement between devices.
  • IoT and OT devices cannot run agents and were not designed to be authenticated, so conventional designs accommodate them by widening the trusted zone.
  • Versa Secure SD-LAN makes segmentation a property of the fabric, enforcing Zero Trust and microsegmentation as close to the endpoint as the deployment allows.
  • Because policy, management, and visibility span WAN and LAN on one operating system, the segmentation requirement is met without introducing a parallel policy model or a separate vendor stack.

Ask an enterprise security team how far along their Zero Trust program is and the answer is usually specific and confident. Remote access was addressed first, and the architecture there is well understood. The WAN edge followed, and policy at that boundary is now enforced continuously. Both were substantial pieces of work, and both are complete.

Then ask what happens when someone plugs a laptop into a conference room port, or when a building management controller comes online in a wiring closet, and the answer becomes noticeably less specific. In most enterprises the physical campus network is the part of the estate that the Zero Trust program has not reached. It is also, by device count and by the breadth of what it can reach, the largest high-trust zone the organization operates.

Where Zero Trust Programs Actually Stop

For most organizations, the campus fell behind for structural reasons, and not for lack of priority. Remote access and the WAN edge each had a single point of entry to instrument, like a VPN gateway or an SD-WAN edge, so covering that one point did most of the job. However, the campus does not work in the same way. Every wall jack and access port is its own control point, so there was never one place to enforce policy from. The devices connecting to those ports were also all over the map, and a lot of them could not be centrally managed. Furthermore, the campus already had VLANs and port-based authentication, which looked enough like segmentation that it was easy to call the problem solved and move on.

The result is a gap: while an employee gets constantly re-checked, identity-verified access when working from a hotel room, that same employee has much looser access once they are sitting at a desk in the office.

Why the Flat Network Persists

Flat and coarsely segmented campus LANs are not the product of oversight. They are the product of an architecture design goal that was, for a long time, entirely correct: the LAN existed to make things reachable. Its job was to ensure that a device plugged into a port could get to what it needed with minimal configuration and minimal support, and it does that job well.

Segmentation runs against that grain. Every segmentation boundary added is a boundary someone has to design, document, test, and eventually explain when something legitimate stops working. In practice, the safe engineering choice at each individual decision point is the broader zone, because the broader zone generates fewer support tickets. Repeat that choice across a decade of incremental change and the outcome is a network with far fewer meaningful internal boundaries than its documentation suggests.

VLANs and Port Authentication Were Never a Segmentation Strategy

VLANs establish reachability boundaries. They are effective at that and remain a reasonable structural tool to meet the network’s original design goals. But what they do not provide is comprehensive and dynamic policy between endpoints within a zone, which is where the majority of east-west traffic actually flows. More specifically, a boundary drawn at the subnet level does not assess whether one device inside it should have lateral movement to reach another device within the subnet. VLANs only define the outer boundary in which devices may communicate.

Port-based authentication using NAC, similarly, does what it was architecturally designed to do. It makes an admission decision at connection time and answers the question of whether this device may join the network. While that decision is valuable, it occurs at a single point in time when the initial connection is attempted. In addition, an authenticated user is typically granted access to a segmented zone rather than to specific resources within it. Continuous assessment of identity, device posture, and application context with least privilege access is a different function, and treating a one-time admission check as a substitute for continuous checks is where the gap opens.

In an environment built this way, a device that is functioning normally and a device that has been compromised present the same profile to the network, because both were admitted correctly and both are operating inside a designated, segmented zone that permits broad internal reachability. The network is not failing at its job. It is doing exactly what it was designed to do.

The Problem Devices Made Unavoidable

What has changed in the campus is the composition of the device population. A modern campus network today carries user endpoints alongside building systems, medical equipment, industrial controllers, cameras, and sensors. Many of these modern endpoints cannot run an agent, cannot participate in a posture check, and in many cases were never designed to be authenticated at all. Segmentation at this scale cannot be retrofitted easily by device class. There are too many devices, they change too often, and a meaningful proportion of them cannot be inventoried reliably.

Conventional designs accommodate that population by widening the trusted zone, because a per-device exception process does not scale past a few dozen devices. That accommodation is the opposite of what a least-privilege model requires, which means segmentation has to attempt to be something the network does using what it can observe about a device, rather than something an IT team can configure and secure per endpoint.

Segmentation as a Property of the Fabric

Versa Secure SD-LAN solves this problem by embedding Zero Trust, microsegmentation, and policy-based access control directly into the LAN architecture, and enforcing them as close to the endpoint as the deployment allows. The distinction that matters is between segmentation as an overlay, and segmentation as a property of the fabric itself.

In an overlay model, the network provides reachability and a separate product restricts it. This means two systems hold two views of what should be permitted and someone has to keep them aligned. In the fabric model, enforcement is where the device connects, expressed in the same policy the organization has already written for the WAN, and running on the same operating system. There is no second place for the same intent to live, and therefore no drift between them.

Practically, this means device identification and IoT and OT visibility, microsegmentation, Layer 4 through Layer 7 controls, firewall, and intrusion prevention sit in one platform rather than in adjacent products connected by integration. Policy follows users and devices across LAN, WAN, and cloud, so enforcement does not vary according to where someone happens to be working. Real-time visibility across users and IoT and OT devices comes from a single console, which matters as much as the enforcement itself, since a segmentation policy that cannot be observed is a policy nobody will tighten.

What Changes When Enforcement Reaches the Edge

The immediate effect is on east-west movement. When policy is enforced at the point of connection and expressed per device and per application rather than per subnet, the reachable surface available from any single endpoint narrows substantially. Unauthorized lateral movement stops because detection and containment is happening quickly and starts based on the architecture.

The second effect is operational, and it tends to be the one that decides these programs. A single policy model across WAN and LAN removes the reconciliation work that separate systems create, which is where a disproportionate share of troubleshooting time goes. Configuration is automated rather than hand-maintained, so the design stops depending on the small number of people who remember why the exceptions exist. Mean time to resolve improves for a fairly unglamorous reason, which is that there is one system to look at.

Finishing the Program You Already Started

For organizations that have completed the remote access and WAN edge phases of a Zero Trust program, extending the same model into the campus with Versa Secure SD-LAN is a continuation rather than a new initiative. The principle is already agreed, the sponsorship already exists, and the policy model has already been written and tested. What has been missing is a control point in the LAN capable of enforcing it.

For an organization already running the Versa fabric in the WAN, that control point is an extension of what is in production rather than a parallel architecture to procure, staff, and learn. The segmentation requirement gets met from the platform already deployed, which is a shorter path than any evaluation, and it closes the one zone in the enterprise where the Zero Trust model has, until now, stopped at the door.

FAQs

On a flat or coarsely segmented campus LAN, VLANs only draw an outer reachability boundary. They do not police east-west traffic between devices inside that boundary, meaning a compromised endpoint looks identical to a healthy one once it's admitted. LAN microsegmentation closes that gap by enforcing policy per device and per application at the point of connection rather than per subnet, which narrows the reachable surface from any single endpoint and stops unauthorized lateral movement at the source instead of relying on inspection after the fact. Versa Secure SD-LAN builds this in as a property of the fabric itself so that microsegmentation logic lives and connects with security policy in one place rather than in a bolt-on overlay that has to be kept in sync with the network's actual reachability rules.

802.1x and NAC make a one-time admission decision, answering the question of whether a device may join the network, but not the question of whether it should be allowed to reach everything inside the zone it was placed in. These technologies don't provide the continuous evaluation of identity, posture, and application context that least privilege access requires once a device is in the network. Security architects extending Zero Trust from the WAN edge into the LAN need a control point that treats access as an ongoing decision rather than a connection-time gate, which is the specific function that Versa Secure SD-LAN microsegmentation, not NAC alone, is designed to serve.

The campus is typically the largest high-trust zone left in the enterprise, and it now carries user endpoints alongside cameras, sensors, building systems, and industrial or medical equipment. Widening the trusted zone to accommodate those devices directly undercuts least privilege access and leaves IoT and OT traffic largely unmonitored for lateral movement in the event they become compromised. For a CISO reporting on Zero Trust maturity, this gap is the reason regulators and auditors increasingly ask about east-west controls specifically, not just perimeter and remote-access posture.

Adding a standalone segmentation or microsegmentation product onto an existing LAN creates two systems with two views of what should be permitted, creating work for the network team that has to keep them aligned. This can lead to configuration drift and increase monitoring and troubleshooting overhead, a common cause for stalled Zero Trust efforts in the LAN. Versa Secure SD-LAN avoids this problem by deploying LAN policy on the same operating system and the same policy model already used at the WAN edge. Microsegmentation, device identification, IoT and OT visibility, and Layer 4–7 controls sit in one platform with a single console. For teams that already run Versa in the WAN, this means the LAN control point is an extension of production infrastructure rather than a new architecture to procure, staff, and learn.

Subscribe to the Versa Blog

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Related Posts