Network Segmentation
Isolate VLANs, DMZs, and security zones with policy enforced at every boundary.

Overview
Segmentation limits blast radius when a host is compromised. Nebero applies zone-based policies between LAN, DMZ, and WAN interfaces so east-west traffic is inspected and controlled, not just north-south perimeter flows.
Capabilities in this category
VLAN support
Segment broadcast domains and apply policies per VLAN.
802.1Q trunking on physical and logical interfaces separates departments, guest Wi-Fi, and IoT devices. Inter-VLAN routing passes through the firewall so every cross-segment flow is subject to unified policy.
DMZ configuration
Host public-facing servers in an isolated demilitarized zone.
Dedicated DMZ interfaces place web, mail, and DNS servers between untrusted and trusted networks. Strict inbound and outbound rules permit only required service ports while preventing lateral movement into the internal LAN.
Zone-based security policies
Define security zones and control traffic between them.
Map interfaces and VLANs to named zones (e.g. LAN, WAN, DMZ, VPN) and write policies that reference zone pairs instead of individual IPs. Simplified rule sets scale as the network grows without policy sprawl.
