Encrypted traffic still needs network policy
Encryption protects the contents. It says nothing about whether that conversation should be happening at all.
An encrypted connection from a workstation to a server in another country is still a connection that may have no business existing. Policy about who may talk to whom operates on a different question from confidentiality, and teams occasionally conclude that because everything is encrypted, network controls are redundant.
More on Network segmentation
- Segmentation limits paths, not compromise itselfBulkheads, not armour
- Every firewall allow rule creates a permitted pathEvery rule is a hole
- Flat networks turn local trust into broad reachabilityOne floor, no walls
- Microsegmentation moves boundaries closer to workloadsMove the fence inwards
- Management paths can bypass segmentationOver the checkpoint
- Default deny makes new paths deliberateNothing moves until a lever is pulled
