Important Notice: Our web hosting provider recently started charging us for additional visits, which was unexpected. In response, we're seeking donations. Depending on the situation, we may explore different monetization options for our Community and Expert Contributors. It's crucial to provide more returns for their expertise and offer more Expert Validated Answers or AI Validated Answers. Learn more about our hosting issue here.

How can subnetting increase network security?

0
Posted

How can subnetting increase network security?

0

Sub-networks can be segregated, which in itself is a huge security upside. Also most virus’, threats, spyware and hackers base their attacks on basic network configurations, making a network configuration which is not standard makes such threats harder to intrude and cause any damage.

0

If you had all of your computers on one subnet, they would all be affected by a broadcast based attack. By subnetting you create more broadcast domains and this reduces the risk of broadcast attacks. Hope this makes sense.

0

divides the network up so that devices on the network cant access the entire network

0

Divide and conquer! If all your network was in one subnet, and some device gets compromised, all of yout network and all devices are visible. That compromise could be anything from a virus or work to a hacker. You are then trying to recover all of it at once, and all devices are vulnerable – by the time you clean and secure one, others will potentially be compromised. Breaking the network into subnets increases the number of places once can add security or segregate a network. That can be things like packet filters or full blown firewalls, It also gives IDS systems an easier time, as there is less traffic for them to track, though you would need more. Should a device be compromised in a heavily subnetted network, the initial impact it more likely to be constrained to the subnet, which makes it easier to target your response – all users on the second floor are reporting poor performance for example. That means you have a much smaller haystack to look in to find the culprit to begin with

0

Subnetting is not meant to increase network security, it was origionally intended to prevent large amounts of Ethernet packets and the risk of packet collision. A combination of subnetting, vlans, and packet filters can be used to achieve of a level of security, however the packet filters on a gateway (or a firewall connected between the gateway and switch ) are more the key points of this type of security set up.

What is your question?

*Sadly, we had to bring back ads too. Hopefully more targeted.