QS-WAN · Segmentation

Microsegmentation you draw, not describe

Microsegmentation in QS-WAN means you build the segments yourself. Create VLANs and LANs, reserve the address space each one uses, and draw the edges that decide which segment reaches which. Your switches, servers and cabling stay exactly where they are.

What it is

Almost nobody designs a flat network. They inherit one.

A flat network is rarely a decision. It is what a network turns into when it grows faster than the ability of anyone to draw it: ten years of adding a printer here, a test machine there, and a contractor who needed access on a Friday afternoon. The cost arrives later and it is always the same shape. On a flat network reachability is the default, and every exception is work somebody has to remember to do. Segmentation flips which one is the default.

Segments you create and delete

VLANs and LANs are objects you make and remove in the console, on the gateway that serves them. Adding one does not ask you to touch the hardware underneath, and deleting one does not leave a range stranded.

An address plan that lives with the network

Each VLAN and LAN reserves its range as part of being created, so two segments cannot quietly claim the same one. The plan stops being a spreadsheet somebody remembers to update.

Two kinds of edge, and they behave differently

A VLAN to LAN edge is one way by construction, with SNAT as a per-edge option. A VLAN to VLAN edge is applied symmetrically, so both directions open together and there is no state where one side thinks it is talking and the other thinks it is closed.

Two segments do not talk until you say they do, and the saying so is a thing you draw rather than a thing you describe.

The mechanism

Three edges, and only one of them opens both ways

Draw the edges and watch the arrowheads. The one between the two VLANs grows a head at each end, because it opens both directions together. The two into the server room never grow a second head, on any setting, and that is the whole point of the section.

Accounts10.20.4.0/24zero trustContractors10.20.9.0/24zero trustServer roomexisting LAN, discoveredSNAT: offboth waysone wayone waythe LAN never reaches back
1 of 4 directions open

Two VLANs, Accounts on 10.20.4.0/24 and Contractors on 10.20.9.0/24, and one existing LAN called Server room that the gateway discovered. Three edges can be drawn. The edge between the two VLANs is symmetric: switching it on opens Accounts to Contractors and Contractors to Accounts together, and there is no state where one believes it is talking and the other believes it is closed. The two edges into the LAN are one way by construction, so a VLAN reaches the server room and the server room never reaches back, on any setting. SNAT is an option on the edge, so traffic can arrive at the LAN wearing the address of the gateway instead of the address of the VLAN. With only the Accounts edge drawn, one of the four possible directions is open.

Why this exists

Four things that go wrong without it

Reachability is the default, and nobody chose it

The accounting server and the visitor laptop sit in the same space because nothing in between was ever asked the question. That is inheritance, not architecture.

Every exception is somebody remembering

On a flat network the list of things that should not talk to each other lives in the heads of two or three people. That list does not survive a holiday.

Direction is where it actually bites

Most access problems are not whether A reaches B. They are that A reaches B and nobody checked whether B reaches A.

The diagram is wrong the week it is drawn

A picture kept separately from the network starts drifting immediately. If the map is not the same object as the rules, it is a story about the network.

What you get

One edge, two arguments

The person who runs the network wants the direction to be right without having to check it every Friday. The person who signs the invoice wants to know what getting there costs. Same edge, two very different questions.

For the network

Direction is built in, not configured

A VLAN to LAN edge is one way because of what it is, not because of how it is set. There is no checkbox to leave in the wrong position at five on a Friday.

One address plan, held by the network

Ranges are reserved as segments are created, so two VLANs cannot end up sharing a range by accident and no file has to be kept honest by hand.

Nothing to explain to anybody

There is no segment to pick on the device and no range to type. Which VLAN a device belongs to is decided in the console, by whoever is supposed to decide it.

For the business

No forklift, and no re-addressing

Adjacent LANs are discovered on the gateway side and connected with an edge, so the network you already paid for gets segmented rather than rebuilt.

A smaller thing to defend

Two segments do not talk until you say they do. That is a shorter answer to give an assessor than a flat network and a list of exceptions people are holding in their heads.

The diagram stops lying

The map is the same object the edges are drawn on, so it is current by construction. When someone asks how the network is separated, you show them.

How it works

Three steps, and your people take part in one

Somebody opens the app and connects

Your colleague in accounts opens the QNova Client and presses connect. One button. There is no segment to choose, no address range to type and no profile to pick from a list that went round by email. The VLAN that device lands in was decided before they woke up, which is why there is nothing for them to get wrong and nothing for them to call you about.

You see where it landed, and what that segment reaches

The same connection shows up in QS-WAN with the context the person on the device never had: which VLAN the device is in, which address range that VLAN holds, and every edge leading out of it. Nobody had to tell you, and there was no walk to a desk to find out.

You change what it reaches, from where you are sitting

Click an edge to turn communication on or off, and the change applies symmetrically, the same way it does everywhere else in the product. Around the segment you hang the rules that make it mean something: rules per gateway and per user, reapplied when a device reconnects, DNS profiles assigned per VLAN, and weekly schedules that restrict the hours a VLAN is available. If a gateway is offline, the console says the intent is saved and converges when it is reachable again, instead of showing a green tick it has not earned.

Before you start

You need the gateway that already serves those machines. Nothing is re-addressed, nothing leaves the rack, and the switches and cabling stay exactly as they are.

In detail

Network microsegmentation only helps if somebody can see it

Map

Every segment and every edge, on one screen

The Network Map draws gateways, VLANs, LANs and the links between sites on one screen. The legend is semantic rather than decorative: Unidirectional, Bidirectional, Disabled, Zero trust. Click an edge to turn communication on or off, and the change applies symmetrically.

The map matters more than it sounds. Segments nobody can picture get merged back together by the first person in a hurry, and that is how flat networks come back. Because the map is the same object the edges are drawn on, it cannot drift away from what is actually configured.

Trust

Zero trust is a separate control from the tunnel mode

Changing one does not change the other, and that is worth reading twice. A VLAN can run in split tunnel and still be default-deny.

Sending only company traffic through the tunnel is a routing decision. Refusing anything the segment was not told to allow is a policy decision. Keeping them apart is what lets you take the bandwidth win without handing back the posture, and there is more on the routing half in split tunnelling.

Where this earns its place

Four mornings this changes

The contractor who needed access on a Friday

They get a segment of their own with one edge drawn to the one thing they need. When the three weeks are up, the edge goes and so does the segment.

Remote people reaching the network that was already there

A VLAN to LAN edge connects them to the servers, one way by construction, with SNAT on the edge if the LAN should see the gateway address instead.

Two departments that have no business talking

You simply do not draw the edge. That is the whole configuration, and there is nothing to maintain, because the absence is the rule.

An assessor asks how the network is separated

You open the map. The segments, the ranges and the directions are the same objects the network is actually running, not a drawing kept alongside it.

Works better with

What hangs off a segment once it exists

The map where the segments and the edges are drawn, and where you click one to change it. Segments nobody can picture do not survive.

Who gets onto the network, from where and at what hours, decided before anything reaches a segment. Rules hang on each segment too.

A profile per VLAN, so name resolution becomes part of what the segment means instead of a separate argument.

Adjacent LANs are discovered gateway-side and connected with an edge. This is how the network you already own gets segmented rather than rebuilt.

What this does not do

The limits, because they are what make the rest believable

It does not replace the network you already have

Adjacent LANs are discovered on the gateway side and connected with an edge. Nothing is re-addressed, nothing is racked and nothing leaves the building.

It does not watch the segments for you

There are no analysts of ours looking at your traffic, because this is a product rather than a managed service. What it gives you is the boundary and an honest map of it.

It does not prove an offline gateway has obeyed you

A saved change proves the intent was recorded. With the Tower Connection off, edits save but are not pushed, and they converge when the gateway is reachable. The console says so.

It does not design the segments for you

Which groups deserve their own VLAN, and which edges are worth drawing, is your architecture. What this gives you is objects small enough to say it precisely and a map honest enough to show what you actually said.

Questions people ask

The ones that come up first

What is microsegmentation?

Microsegmentation is splitting a network into small segments and deciding, per pair, which segment can reach which. In QS-WAN you do it by creating VLANs and LANs, reserving the address space each one uses, and drawing edges between them. Two segments do not communicate until you draw the edge that says they can.

Do I have to replace my switches?

No. Segments are objects created in the console on the gateway that serves them, and adjacent LANs are discovered gateway-side and connected with an edge. Nothing is re-addressed and nothing leaves the rack.

If a VLAN can reach a LAN, can the LAN reach back?

No, not on that edge. A VLAN to LAN edge is one way by construction, so the VLAN reaches the LAN and the LAN does not reach back. The symmetric case is VLAN to VLAN, which opens both directions at once and tells you so.

Is network microsegmentation worth it on a network this small?

It is worth it as soon as you have two groups that should not share a space, which is most networks with more than one kind of user. The work here is drawing a handful of segments and a handful of edges, not running a project. Small networks get flat the same way big ones do, one printer and one contractor at a time.

Is zero trust the same as the tunnel mode?

No. They are separate controls and changing one does not change the other. A VLAN can run in split tunnel and still be default-deny. Sending only company traffic through the tunnel is a routing decision; refusing anything the segment was not told to allow is a policy decision.

What does SNAT do on an edge?

It is a per-edge option, not a global setting. With it on, traffic arrives at the LAN wearing the address of the gateway rather than the address of the VLAN, which is often what the existing servers expect to see.

Bring your flat network. We will draw the edges.

You say how the network is laid out today and which two groups have no business talking to each other. We put the segments and the edges on a map, using your layout rather than a demo one, for as long as you need. It is free and there is nothing to sign.

Scroll to Top