• Skip to primary navigation
  • Skip to main content
site logo
  • About
    • Approach
    • Partnerships
    • Mission
    • Leadership
    • Awards
    • Arraya Cares
  • Solutions
    • Solutions

    • Hybrid Infrastructure
      • Hyperconverged
      • Infrastructure as a Service
      • Servers, Storage, and Virtualization
      • Data Protection
      • Disaster Recovery & Business Continuity
    • Apps & Data
      • AI
      • Automation
      • Customizations
      • Visualizations & Integrations
      • Migrations
    • Network
      • Enterprise Networks
      • Wireless Connectivity
      • Cloud Networking Solutions
      • IoT
    • Cybersecurity
      • Endpoint Security
      • Network Security
      • Cloud Security
      • Application Security
    • Modern Workplace
      • Microsoft Licensing
      • Productivity & Collaboration
      • Modern Endpoint Deployment & Management
      • Microsoft Compliance & Risk
      • Backup
      • Cloud
  • Services
    • Services

    • Managed Services
      • Service Desk
      • Outsourced IT
      • Managed Security
      • Managed NOC
      • Arraya Adaptive Management for Microsoft Technologies
      • ADEPT: Arraya's White Label Program
    • Advisory Services
      • Assessments
      • Strategy
      • vCTO
      • vCISO
      • Enterprise Architecture
    • Staffing
      • Infrastructure Engineering
      • Security & Compliance
      • Application & Software
    • Professional Services
      • Project Management 
      • Systems Integration 
      • Mergers & Acquisitions
      • Knowledge & Skills Transfer 
  • Industries
    • Education
    • Finance
    • Healthcare
    • Legal
    • Manufacturing
    • Software and Services
  • Insights
    • News
    • Blog
    • Events
    • Videos
    • Case studies
  • Careers
  • CSP Login
search icon
Contact Us

Keep Your Network Secure with SD-WAN & Segmentation: 3 Steps

This is the final post in our ongoing, deep dive series on the subject of segmentation. Each post has been written by a member of Arraya’s technical or tactical teams, focusing on a specific piece of this extremely broad, highly transformational, topic. SD-WAN segmentation

Does your network need “more” segmentation? The answer is most likely “yes.” Even if you have access to most other corporate assets, executive compensation plans are usually not available for just anyone to see. But, what protection are you providing for your company’s data? Camera / video data, physical security and building access systems, all house employee personal information. These systems can and do become compromised. They are some of the last devices to be moved to the cloud and its promise of protection. With some basic filtering and segmentation, a considerable amount of risk can be mitigated. We can take this process and replicate it over a Cisco-backed wide area network.  While we often have strong policies and procedures at corporate headquarters, remote locations often don’t have the same budget or mindset. These remote locations often generate a significant – and overlooked – risk.

Software defined or “SD” WAN doesn’t bring us the ability to filter corporate sites. Service providers have used segmentation and network filtering for as long as they have been around. This is no simple feat. There is an entire CCIE discipline dedicated to the complexity of popping labels, VRF leaking, L3VPN and carrier based Ethernet configuration. By choosing the right SD-WAN provider, you can get some of these features without the need for your own team of CCIEs.

Architects build today’s networks using templates and address pools instead of console cables and notepads. This allows us to keep our deployments, security, and design consistent. In case of a lost or compromised device, we can quickly revoke its certificate(s) and remove the device from the network.

There are essentially three key segmentation building blocks.

Building Block #1: Classification

This is the first stage of segmentation.  On the WAN edge, admins traditionally did this with layer 4 access-list matching on an IP or port. This evolved to NBAR, Cisco’s technology which can work to identify traffic dynamically instead of using static lists of ports. The current Cisco NBAR2 technology can recognize over a thousand applications.  Protocol packs apply incremental “hitless” updates identifying today’s plain text and encrypted applications with no need for decryption.

Recently, new NBAR “groups” and “attributes” have made network admins’ lives easier. A high level list of “traffic classes,” such as VOIP-telephony, real-time-interactive, network-control and bulk data, are created and updated by default. The network administrator can additionally apply an attribute called “business-relevance.” This helps mark down or reclassify applications like Apple FaceTime, which identifies itself as real-time traffic but is most likely not relevant for work time at your job.

Using these classification abilities, we can match traffic for guest, contractor, and employees and then “tag” the traffic for appropriate filtering. Depending on the environment, this may be Cisco SGT, VRF or a DSCP value. This will come up again further down the road when enforcing filtering.

Building Block #2: Filtering

The next step in the process is to determine what we want to filter and segment. Easy use cases are for guests and unmanaged systems. Filter or segment anything your organization can’t manage on network. This isn’t always easy or even possible. By filtering traffic from unprotected locations, we can reduce risk and take more of a “Whitelist” approach and explicitly permit traffic that is required.

Just about every SD WAN solution gives you the ability to segment and separate traffic out of the box. “Leaking” and filtering traffic is possible with most SD WAN solutions. However, many organizations prefer to filter this traffic through traditional firewalls. This keeps filtering of security zones consistent across an organization specifically for those with existing security standards and approved methods or procedures.

Building Block #3: Validation / Reporting

The final piece of any segmentation project is validation and reporting. IT should document, validate and audit all high level policies. Adding or editing security zones necessitates additional testing and validation to ensure conformance.

To learn more about segmentation and its role in today’s IT landscape, reach out to our team of experts by visiting: https://www.arrayasolutions.com//contact-us/.  

Arraya Insights
Back to Top
Arraya Solutions logo

We combine technological expertise and personal service to educate and empower our customers to solve their individual IT challenges.

518 Township Line Road
Suite 250, Blue Bell, PA 19422

p: (866) 229-6234     f: (610) 684-8655
e: info@arrayasolutions.com

  • Careers
  • Privacy Policy
  • Contact Us

© 2025 Arraya Solutions. All rights reserved.

Facebook Twitter YouTube LinkedIn
Manage Cookie Consent
We use cookies to enhance your experience. By selecting “Accept,” you agree to our cookie policy.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
Manage options Manage services Manage {vendor_count} vendors Read more about these purposes
View preferences
{title} {title} {title}