Open navigation menu - Kieri Solutions
Network hardening near Baltimore MD, Frederick, Rockville, Gaithersburg and DC

Network hardening near Baltimore MD, Frederick, Rockville, Gaithersburg and DC

Best practice network segmentation and hardening prevents pivot attacks NIST

In this article

How to stop lateral movement through your networks

Kieri Solutions implements deny-by-default firewalls and network segmentation for government, small, and medium businesses. This is a specialized skill which requires very strong knowledge of a broad range of platforms as well as network security. If you would like to chat about your network hardening and compliance project, email us at info@kieri.com

If you want to prevent damage from hackers and ransomware attacks, you need to perform network hardening and segmentation.

NIST security publications encourage โ€˜defense in depthโ€™ as a best practice.ย  They recommend creating multiple network segments with strong firewalls in between.ย  ย The diagram above shows a cost effective segmentation design that is appropriate for medium businesses.

NIST control 3.13.6 Compliance

NIST and DFARs compliance projects require implementation of control # 3.13.6: Deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception).

This is one of the most difficult cybersecurity controls to comply with. Almost all businesses have wide open (allow all) network communications, except for the external firewall. Open communication places the business at risk of data breach, intellectual property theft, insider threat, and extensive damage from malware attacks. Attempts to secure your network by denying traffic by default will often cause system outages unless you have expert assistance.

By separating your network into multiple segments, you limit the damage that could occur from cyber-security threats.

For example, many ransomware attacks will spread to every vulnerable computer in the same network segment as the original compromised computer. Rather than have your workstations AND server data destroyed, wouldnโ€™t it be better to limit the damage to just a few workstations?

Several IT Cybersecurity compliance frameworks require the use of De-Militarized Zones (DMZ) and Secure Sensitive Networks. For example, if your business processes credit cards, the PCI compliance program will require that you separate credit card databases from externally-facing servers.

Deny-by-default DMZ Firewall

A secure DMZ is the first improvement you should consider.ย  It is also an important step for PCI compliance.ย  Your externally-facing servers are at high risk from Internet-based attacks.ย  ย Once an internal server is penetrated and taken over by a hacker, they โ€œpivotโ€ to attack the rest of your network.ย  Any penetration tester will tell you that once they are inside the network, the hard work is done.

Examples of servers that should be in a DMZ:

  • Outlook Web Access and Outlook direct (Exchange Client Access Server)
  • Remote access (Citrix terminal servers and Remote Desktop for users or IT staff)
  • Application servers that transfer data to-or-from other companies
  • Proxy servers
  • Spam filters (Barracudas etc)
  • Electronic faxing
  • Any web server that can be reached from outside
  • Servers that synchronize with โ€œthe cloudโ€ or other businesses

How does a DMZ deny-by-default policy work?ย 

The outside firewall (between your company and the Internet) should already be using deny-by-default policies, at least for traffic coming in from the Internet.ย  ย We will review this to see if it is possible to tighten up any of the policies.ย  For example, many companies allow remote access to a terminal server from anywhere on the Internet.ย  This is extremely risky.ย  We would recommend reducing this remote access to specific network addresses (such as vendor networks) and using VPNs for traveling employees.

Where it makes sense, we also want to restrict outbound communication through your firewall.ย  Once a hacker has accessed your sensitive information, they generally want to make a personal copy of it.ย  They do this by sending it through your firewall.ย  Blocking unusual traffic makes it harder for the bad guys to perform a data breach.

Creating a DMZ adds a second firewall layer between your externally-facing servers and your internal network.ย  ย This restricts the network traffic that moves between DMZ servers and the rest of your network.

How is a DMZ with strong firewall implemented?ย 

Very carefully.ย  ย This is not a fast process.ย  The last time we created a DMZ for a medium sized business (500m/year revenue and 10 servers inside the DMZ), it took three weeks, about 100 billable hours, and a two-month on call period to complete.ย  But we researched and tested everything thoroughly as we went, which minimized user impact.ย  If anyone tells you that this is a fast or easy process, they are probably leaving allow-all rules between the segments, which defeats the entire purpose.

  1. Research and planning phase:ย  Carefully review each server, and each server that they communicate with, to identify normal communication channels and port usage.ย  Create written back-out plans so that if business is impacted, we can flip a switch and get the servers communicating until we find a solution.
  2. Establish DMZ network: Migrate server networking to the DMZ.ย  Other servers will need to update their connection information for the migrated server.ย  Test thoroughly.
  3. Enforce deny-by-default policies:ย Create a firewall policy set for each DMZ server which allows only necessary communication between the outside and the inside.ย  Test thoroughly (this includes restarting services and servers to trigger startup communications).
  4. Monitoring and responsiveness: Engineer is on-call for at least a month to assist with infrequent situations such as month-end accounting jobs.
  5. Documentation and training: Provide configuration management information, firewall and switch configs, and train your staff to manage the new systems.

Sensitive systems internal layer

The next segmentation improvement is to set up a sensitive systems internal layer.ย  This network layer is for the most critical systems: high value targets such as your customer database, proprietary designs, and backups.ย  Core IT systems such as VMware, switch, and firewall managementย  can also be protected here.

How is internal segmentation implemented?ย 

The process is essentially the same as the DMZ, but for the most sensitive systems rather than the least sensitive systems.ย  Servers are only good candidates for this if they have limited communications.ย  For example, an ideal database server would only have one communication channel open โ€“ between it and an application server.

A server that is accessed on multiple ports by regular users (such as a file server or directory server) cannot be fully secured, so it should stay on the internal network.


Internet of Things โ€“ a developing risk

The problem with IoT is that most of the devices are programmed to โ€œcall homeโ€ to their vendor.ย  Depending on the device, they might download updates automatically, or even be remotely managed by the vendor. If the vendor is compromised, each of their devices could be a source of infection to your network.ย 

For example, even if you have a firewall that protects you against inbound threats, your security camera probably opens an outbound connection to its vendor company each day.ย  Normally this is a good thing โ€“ it lets the vendor install patches or centrally manage the device.ย  But if something goes wrong at the vendor, the device could serve as an access point into the inside of your network.

In the last two years, the Internet of Things (IoT) has exploded.ย  Your business might have some of theseโ€ฆ

  • Smart TVs
  • VOIP phones
  • Security cameras
  • Personal assistant devices (Alexas, Siri)ย 
  • Printers
  • Environmental systems
  • Scanners
  • Some โ€œsmartโ€ firewalls such as FortiNet
  • Smart backup devices such as Datto
  • Network Attached Storage (NAS) such as Synology
  • Tablets
  • Battery back-up systems
  • โ€œSmartโ€ lights

There arenโ€™t established industry best practices for IoT devices yet, but we here at Kieri Solutions feel that they should be strongly separated from the rest of the network.ย  Setting up an separate network just for IoT devices is an easy way to do this for your business.


Do I need to buy multiple firewalls or switches?

Most of the time, if you are working with business-quality firewalls and switches, we do not need to buy any new hardware.ย  ย Most professional firewalls / routers such as Cisco, Sonicwall, FortiNet, and WatchGuard have built-in capability for multiple network segments.ย  Most professional switches have VLAN capability, which we can configure for DMZ and sensitive network segments.


Best practice network segmentation and hardening prevents pivot attacks NIST

What is the next step?

Please consider Kieri Solutions for your network hardening and segmentation project. Our employees are trusted by the US military, universities, large, medium, and small corporations.ย  We loveย after-hours work, change management,ย  configuration management, and testing because they reduce risk and keep users working.


Call us: (301) 253-5150


kieri solutions IT consultant service provider cybersecurity logo

Kieri Solutions is a cybersecurity and IT consulting company serving businessesย in Maryland and Northern DC. Silver Spring, Rockville, Gaithersburg, Frederick, Baltimore, Columbia and other nearby cities in MD.

We also assist companies throughout the USA for remote-work projects such as virtualization, Azure, and security policy writing.

Cybersecurity data analysis supporting CMMC Level 2 audit preparation for defense contractors

Talk to an Expert

Tell us where you are with compliance and weโ€™ll map out the next steps for your team.

Don't miss these

Is Your Security Plan Telling the Truth?
Server room corridor lined with racks in a data center covered by a System Security Plan
Is Your Security Plan Telling the Truth?
What Does the Government Actually Require of You Today?
A network of yellow lines connecting round nodes against a dark background.
What Does the Government Actually Require of You Today?
NIST SP 800-171 Rev 3, What Changed and What It Means for Your CMMC Timeline
Man at a desk in a dark office reading text on a computer monitor, NIST SP 800-171 Rev 3
NIST SP 800-171 Rev 3, What Changed and What It Means for Your CMMC Timeline
CMMC Backup Requirements and The Myths Worth Ignoring
Server backup drives in a dark data center supporting CMMC backup requirements for a defense contractor
CMMC Backup Requirements and The Myths Worth Ignoring
How to Prepare for a DIBCAC High Assessment
Analyst reviewing evidence on dark dual monitors while preparing for a DIBCAC High assessment
How to Prepare for a DIBCAC High Assessment
Out of Scope Assets - What the Final Rule Actually Changed
Abstract data cityscape tied to out of scope assets in a CMMC assessment by Kieri Solutions
Out of Scope Assets - What the Final Rule Actually Changed
CMMC Proposed Rule Analysis - What Defense Contractors Need to Know
Dark cybersecurity image with glowing data illustrating CMMC final rule compliance for defense contractors
CMMC Proposed Rule Analysis - What Defense Contractors Need to Know
CMMC Phase 2 Suspended and What Defense Contractors Need to Know
Analyst reviewing code while working toward CMMC and NIST 800-171 compliance
CMMC Phase 2 Suspended and What Defense Contractors Need to Know
CUI Assets - What Assessors Actually Evaluate
Abstract network of nodes tied to CUI assets and CMMC scope assessed by Kieri Solutions
CUI Assets - What Assessors Actually Evaluate
Do I Even Have CUI? Understanding What You Need to Protect
Abstract data network tied to finding CUI on a defense contractor network with Kieri
Do I Even Have CUI? Understanding What You Need to Protect
Why the DoD Wants Security Protection Data Protected Like CUI
Abstract data network tied to security protection data and CMMC scope assessed by Kieri
Why the DoD Wants Security Protection Data Protected Like CUI
Why Your CMMC Gap Analysis Might Be Worthless - 110 Practices vs 320 Assessment Objectives
Cybersecurity professional conducting CMMC gap analysis for a defense contracting organization
Why Your CMMC Gap Analysis Might Be Worthless - 110 Practices vs 320 Assessment Objectives
Building a CMMC Level 2 Compliant Network You Can Actually Manage
Network architecture visualization for a CMMC Level 2 reference architecture built on Microsoft 365 GCC High
Building a CMMC Level 2 Compliant Network You Can Actually Manage
Why Most CMMC Documentation Fails and How to Fix It
CMMC compliance documentation policies and procedures
Why Most CMMC Documentation Fails and How to Fix It
What Passed a DOD Assessment for System Baselining and Inventories
CMMC system inventory and baseline configuration monitoring dashboard
What Passed a DOD Assessment for System Baselining and Inventories
How to Implement Mobile Code Requirements for CMMC Level 2
CMMC mobile code security controls and technical implementation
How to Implement Mobile Code Requirements for CMMC Level 2
What Does "Monitor" Actually Mean in CMMC Requirements?
CMMC monitoring requirements - access control and password security verification
What Does "Monitor" Actually Mean in CMMC Requirements?
The Version 20 Problem and How to Avoid It
CMMC compliance documentation sequence - cybersecurity program management
The Version 20 Problem and How to Avoid It
Build Your Own CMMC Level 2 Compliant Environment with the Kieri Reference Architecture
CMMC Level 2 compliant environment security controls and access management
Build Your Own CMMC Level 2 Compliant Environment with the Kieri Reference Architecture
Inside the KCD - What Makes This Documentation Different
CMMC compliance documentation templates digital security
Inside the KCD - What Makes This Documentation Different
How the Kieri Compliance Documentation and Reference Architecture Work Together
Kieri Compliance Documentation and Reference Architecture working together for CMMC Level 2 compliance
How the Kieri Compliance Documentation and Reference Architecture Work Together
What's Actually Inside the Kieri Compliance Documentation? A Complete Walkthrough
CMMC compliance documentation and reference architecture security controls - fingerprint scanning and access management
What's Actually Inside the Kieri Compliance Documentation? A Complete Walkthrough
CMMC Assessments by Kieri Solutions
Global cybersecurity compliance support for defense contractors under DFARS
CMMC Assessments by Kieri Solutions
CMMC Education: User vs Network Session Termination
Secure IT infrastructure design supporting CMMC Level 2 compliance for defense contractors
CMMC Education: User vs Network Session Termination
CMMC Proposed Rule has been released!ย 
Cybersecurity threat - CMMC compliance
CMMC Proposed Rule has been released!ย 
Interested in the Kieri Compliance Documentation?
Secure data transmission within CMMC compliant network architecture
Interested in the Kieri Compliance Documentation?
How to fix Outlook missing Friday January 13 2023
Interconnected defense contractor networks requiring CMMC Level 2 cybersecurity certification
How to fix Outlook missing Friday January 13 2023
C3PAO Meeting - July 26, 2021 12-1 pm EDT
C3PAO Meeting - July 26, 2021 12-1 pm EDT
NIST SP 800-171 DoD Self Assessment Services
DFARS 252.204-7012 and NIST SP 800-171 requirements
NIST SP 800-171 DoD Self Assessment Services
vSphere Health detected new issues in your environment 6.7
vcenter 6.7 alarm displays vsphere health detected new issue
vSphere Health detected new issues in your environment 6.7
vCenter Health Warning: External Platform Services Controller
vCenter Health Warning: External Platform Services Controller
Synology storage latency and disconnects on VMware
Synology storage latency and disconnects on VMware
Windows Stuck in Recovery Mode Datto driver signing
Windows Stuck in Recovery Mode Datto driver signing
Office 365 MFA App Password Missing Fix
Office 365 MFA App Password Missing Fix
Microsoft Teams Conference Calls & Dial-In Numbers
Microsoft Teams Conference Calls & Dial-In Numbers
C: Drive Full Exchange
C: Drive Full Exchange
Exchange server very slow, services and network blank
Exchange server very slow, services and network blank
Exchange 2016 DAG - 3 servers 2 sites
Diagram showing mailbox servers with active and passive databases. Each database is only active on one server.
Exchange 2016 DAG - 3 servers 2 sites
Netapp 3rd-party CA certificates expiring DeutscheTelekomRootCA2
Kieri Solutions partnering with defense contractors to achieve CMMC Level 2 certification
Netapp 3rd-party CA certificates expiring DeutscheTelekomRootCA2
vCenter 6.7 Memory Exhaustion and vSphere health (Tiny)
warning vsphere health detected new issue memory exhaustion 6.7 vcenter
vCenter 6.7 Memory Exhaustion and vSphere health (Tiny)
Step by Step: Upgrade vCenter VCSA 6.0 (or 6.5) to 6.7
Step by Step: Upgrade vCenter VCSA 6.0 (or 6.5) to 6.7
How to prepare for a DoD CMMC audit and certification
cybersecurity CMMC DoD NIST 800-171 compliance nist 800-53
How to prepare for a DoD CMMC audit and certification
Fix Expired vCenter Root Password (6.5 & 6.7)
Fix Expired vCenter Root Password (6.5 & 6.7)
How to rename Windows Server 2016 Domain Controller
How to rename Windows Server 2016 Domain Controller
Runtime Error Adding Host in VMware vCenter & ESXi
add host a general runtime error occurred vcenter 6.5 6.7
Runtime Error Adding Host in VMware vCenter & ESXi
How to fix Netapp expired self-signed certificate by creating a new one
netapp certificate expired install site cant be reached
How to fix Netapp expired self-signed certificate by creating a new one
How to register a warranty or service agreement on HPE website
hpe hp register account SAR ID service agreement warranty how accept
How to register a warranty or service agreement on HPE website
How to install vCenter 6.7 (and 6.0 and 6.5) with no DNS, only IP address
vcenter ip address no dns
How to install vCenter 6.7 (and 6.0 and 6.5) with no DNS, only IP address
How to disable continuous scrolling on Kindle - turn on page flip
disable continuous scrolling option displays
How to disable continuous scrolling on Kindle - turn on page flip
17hats how to export or convert to Excel CSV TAB XLS workbook
17hats export convert iff to csv tab excel
17hats how to export or convert to Excel CSV TAB XLS workbook
How to fix "Cannot apply changes to this Internet Shortcut" Windows
cannot apply changes to this internet shortcut 2016 2019
How to fix "Cannot apply changes to this Internet Shortcut" Windows
Best Free Computer Incident Response Templates and Scenarios
best free incident response reporting form cybersecurity IT
Best Free Computer Incident Response Templates and Scenarios
Firmware & System Patching Services | DC & Maryland
poweredge server raid reconfigure add disks 1 5
Firmware & System Patching Services | DC & Maryland
Network hardening near Baltimore MD, Frederick, Rockville, Gaithersburg and DC
Best practice network segmentation and hardening prevents pivot attacks NIST
Network hardening near Baltimore MD, Frederick, Rockville, Gaithersburg and DC
VMware vSphere ESX and vCenter Upgrade 5.5 to 6.0 or 6.5 or 6.7 best practices
Best practices and how to install esxi vsphere vcenter vmware and troubleshooting problems during the migration
VMware vSphere ESX and vCenter Upgrade 5.5 to 6.0 or 6.5 or 6.7 best practices
Disaster Recovery & Business Continuity in DC & Maryland
disaster recovery drp bcp hipaa frederick columbia gaithersburg baltimore rockville
Disaster Recovery & Business Continuity in DC & Maryland
VMWare and Netapp consultant in DC, Baltimore, Columbia, Frederick, and Rockville MD
installation services netapp disk shelf baltimore columbia rockville
VMWare and Netapp consultant in DC, Baltimore, Columbia, Frederick, and Rockville MD
SBDC - Intro to GDPR training - Frederick MD
intro gdpr overall sbdc fitci frederick
SBDC - Intro to GDPR training - Frederick MD
GDPR and Human Resources
cybersecurity cyber security hardening compliance firewall design frederick
GDPR and Human Resources
No, your computer isn't slow.
why slow computer pc repair frederick damascus mt airy md
No, your computer isn't slow.
Why you should consider a credit freeze - EquiFax hack
credit freeze equifax hack how to breach innovis
Why you should consider a credit freeze - EquiFax hack
Virtual Servers, Storage, and SAN - Why your servers are slow
cybersecurity compliance design consulting engineering
Virtual Servers, Storage, and SAN - Why your servers are slow
How to un-freeze your laptop like a pro
pc or computer problem repair damascus lisbon mt airy laytonsville
How to un-freeze your laptop like a pro
Upgrade your IT Services for the New Year
managed services it department outsource company frederick columbia germantown gaithersburg
Upgrade your IT Services for the New Year
Dell PowerEdge R730 PERC RAID online reconfiguration
poweredge server raid reconfigure add disks 1 5
Dell PowerEdge R730 PERC RAID online reconfiguration
Dreamhost HTTP error Wordpress media upload and library
dreamhost http error picture disappear upload shared wordpress
Dreamhost HTTP error Wordpress media upload and library
FortiAnalyzer Configuration problems after initial deploy
FortiAnalyzer 5.4 Storage Quota Limits for ADOM root
FortiAnalyzer Configuration problems after initial deploy
FortiAnalyzer Report: User Web Browsing by Category
fortianalyzer custom report users by category who is browsing web goofing off
FortiAnalyzer Report: User Web Browsing by Category
GDPR Consulting - What you need to know
cybersecurity CMMC DoD NIST 800-171 compliance nist 800-53
GDPR Consulting - What you need to know
The #1 Computer Security Threat Just Evolved - RCE Worm
cybersecurity cyber security compliance firewall frederick md
The #1 Computer Security Threat Just Evolved - RCE Worm
Fix vSphere & vCenter Datastore Size Reverting
security design cybersecurity consulting services compliance
Fix vSphere & vCenter Datastore Size Reverting
HP DL360p g8 ESXi 5.5 to 6.5 upgrade conflicting_vibs_error
conflicting vibs error vsphere upgrade metadata consultant vmware
HP DL360p g8 ESXi 5.5 to 6.5 upgrade conflicting_vibs_error
Is your IT person holding the network hostage?
Server Upgrade Cybersecurity Consultant SAN Netapp Frederick
Is your IT person holding the network hostage?
4 Hiring Mistakes When Choosing an IT Company
mistakes when hire IT consultant MSP managed service provider computer support outsourcing
4 Hiring Mistakes When Choosing an IT Company
What you should know about Cloud Computing and Office 365
cloud IT department migration Office 365 Frederick Baltimore Columbia MD
What you should know about Cloud Computing and Office 365
Can You Make Our Nation Safe from Hackers?
Can You Make Our Nation Safe from Hackers?
The Ultimate Way to Protect Against Computer Theft
Kieri Solutions site icon
The Ultimate Way to Protect Against Computer Theft
Small / medium business security concerns
managed services it department outsource company frederick columbia germantown gaithersburg
Small / medium business security concerns
Approaches to security policy
cybersecurity cyber security hardening compliance firewall design frederick
Approaches to security policy

Article

Is Your Security Plan Telling the Truth?
Server room corridor lined with racks in a data center covered by a System Security Plan

Article

What Does the Government Actually Require of You Today?
A network of yellow lines connecting round nodes against a dark background.

Article

NIST SP 800-171 Rev 3, What Changed and What It Means for Your CMMC Timeline
Man at a desk in a dark office reading text on a computer monitor, NIST SP 800-171 Rev 3

No one wants to start from blank templates.

No one wants to start from
blank templates.

Stop starting from blank templates. Get documentation proven through actual CMMC Level 2 assessment.