careers / networking / network segmentation
Networking path

Separate traffic deliberately

Network+: Network Security
Original starter lesson / sources checked 2026-09-30

VLANs split Layer 2 broadcast domains. Devices in different VLANs need routing to communicate across them.

A VLAN boundary alone is not a complete authorization policy. Inter-VLAN firewall rules or ACLs determine which routed traffic is permitted.

Document intended paths and test both allowed and denied traffic. Broad allow rules can undo the isolation you intended.

Hands-on lab

  1. Draw staff and guest VLANs with a router or firewall between them.
  2. Specify that guests can reach the Internet but cannot reach a staff file server, then list positive and negative tests.

Put the lesson to work

Original exam-style practice. Choose the best answer for the stated scenario.

1. Guest Wi-Fi must not reach an internal file server. Which approach best fits?
2. Two VLANs are routed with an allow-all policy. What does the VLAN separation alone provide?

Go deeper

Official CompTIA scope and exam information

Independent practice aligned to selected topics. No endorsement, actual exam items, or pass guarantee. Verify your exam version and use the full official objectives for complete preparation.

WWADD — Choose the tool. Make the move. Build the stack.

FREE REFERENCE · NO LOGINCONTACTPRIVACYTERMS