Chapter 5: Selection & Interfaces

Core product introduction, typical wiring and interface logic, and a comprehensive product function comparison table for all key segmentation components.


5.1 Core Product Introduction

The segmentation architecture relies on a set of core security appliances and software platforms, each fulfilling a specific enforcement or visibility function. Product selection must be driven by the technical requirements derived from the zone design — throughput, session capacity, feature set, and operational integration requirements — rather than by vendor preference alone. The following six product categories represent the minimum viable set for a complete segmentation deployment.

Core Security Product Lineup

Figure 5.1: Core Security Product Lineup — Six key security appliances: Edge NGFW (Palo Alto style), ISFW (Fortinet style), WAF/Reverse Proxy (F5 style), Bastion/PAM server with session recording indicator, SIEM Platform with storage capacity display, and NAC appliance (Cisco ISE style) with 802.1X indicator.

Table 5-1: Core Product Functions and Selection Criteria

Product Category Zone Placement Core Functions Key Selection Criteria Typical Form Factor HA Requirement
Edge NGFW Internet ↔ DMZ Stateful inspection, IPS/IDS, NAT, SSL inspection, application control, URL filtering, threat intelligence Throughput at SSL inspection on, session capacity, IPS performance, HA failover time, management API 2U rack appliance (HA pair) Active-Passive or Active-Active
WAF / Reverse Proxy DMZ L7 HTTP/HTTPS inspection, OWASP Top 10 protection, TLS termination, virtual hosting, bot management, API protection RPS capacity, TLS offload performance, false positive rate, learning mode accuracy, API gateway integration 1–2U appliance or VM cluster Active-Active cluster
ISFW (Internal Segmentation FW) Inter-zone boundaries East-west zone enforcement, stateful inspection, application-aware policy, micro-segmentation support East-west throughput, latency at line rate, rule capacity, VXLAN/overlay support, distributed FW integration 1U appliance (HA pair) Active-Passive or Active-Active
Bastion / PAM Management zone Privileged session proxy, MFA enforcement, session recording, credential vaulting, just-in-time access, audit trail Protocol support (SSH/RDP/VNC/DB), recording storage, MFA integration, SIEM integration, concurrent session capacity 1U appliance or VM Active-Passive with shared storage
SIEM Platform Security zone Log collection and normalization, correlation rules, alerting, threat hunting, compliance reporting, SOAR integration EPS (events per second) capacity, storage retention, correlation rule library, SOAR integration, search performance 2–4U appliance or distributed cluster Cluster (3+ nodes)
NAC (802.1X) Access layer / Office zone Device authentication, posture assessment, VLAN assignment, guest portal, rogue device detection, endpoint profiling Concurrent endpoint capacity, posture check coverage, guest workflow, switch/AP vendor compatibility, MDM integration 1U appliance or VM cluster Active-Passive or cluster

5.2 Typical Wiring and Interface Logic

The interface assignment design maps each physical port on a security appliance to a specific zone, with a defined trust level and a set of permitted traffic flows. Correct interface assignment is critical — a misconfigured interface that places a high-trust zone on the wrong port can create an undetected security gap that persists for years. The interface logic diagram below shows the standard port assignments for both the edge NGFW and the ISFW, including the HA sync port, out-of-band management port, and data plane ports.

Interface and Connection Logic Diagram

Figure 5.2: Interface and Connection Logic Diagram — NGFW front panel showing physical port assignments (WAN/orange, DMZ/yellow, Office/blue, Production/green, Management/teal, HA Sync/red, OOB MGMT/gray) with logical zone assignment mapping and trust level badges, plus ISFW interface assignments on the right panel.

Table 5-2: NGFW Interface Assignment Reference

Interface Zone Assignment Trust Level Cable Color Speed Notes
eth0/0WAN / Internet0 (Untrusted)Orange1–10GbpsDual ISP if available; no private IPs
eth0/1DMZ30 (Semi-trusted)Yellow1–10GbpsConnects to DMZ switch; WAF/proxy behind
eth0/2Office / User50 (Low-Medium)Blue1–10GbpsConnects to Office core switch
eth0/3Production70 (Medium)Green10–25GbpsConnects to Production ISFW or core switch
eth0/4Management90 (Privileged)Teal1GbpsConnects to Management zone switch
eth0/5HA SyncN/ARed1–10GbpsDirect cable to HA peer; no switch in path
MGMTOOB Management90 (Privileged)Gray1GbpsDedicated OOB management network

Table 5-3: ISFW Interface Assignment Reference

Interface Zone Assignment Trust Level Cable Color Speed Notes
Port1Production-App tier70 (Medium)Green10–25GbpsApplication servers; load balancer uplink
Port2Production-Data tier85 (High)Purple10–25GbpsDatabase cluster; storage systems
Port3Management90 (Privileged)Teal1GbpsBastion/PAM access only
Port4Security / SOC90 (Visibility)Dark Blue1–10GbpsLog push to SIEM; scanner reach
HA-SyncHA SynchronizationN/ARed1–10GbpsDirect cable to ISFW peer

5.3 Core Product Function Comparison Table

The following comprehensive function table compares the capabilities of the six core product categories across the dimensions most relevant to segmentation deployments. This table is intended to support vendor evaluation and RFP development — each row represents a capability that should be verified during proof-of-concept testing.

Function / Capability Edge NGFW WAF ISFW Bastion/PAM SIEM NAC
Stateful packet inspection✓ Core✓ L7✓ Core
IPS / threat prevention✓ Full✓ Web✓ Partial
SSL/TLS inspection✓ Full✓ Full✓ Partial
Application identification✓ Full✓ HTTP✓ Partial
URL / category filtering✓ Full✓ Partial
MFA enforcement✓ VPN✓ Web✓ Core✓ 802.1X
Session recording✓ Core
Credential vaulting✓ Core
Log collection✓ Self✓ Self✓ Self✓ Self✓ All sources✓ Self
Correlation / alerting✓ Core
Device posture check✓ Partial✓ Partial✓ Core
VLAN / zone assignment✓ NGFW zones✓ ISFW zones✓ Dynamic VLAN
API / automation interface✓ REST/XML✓ REST✓ REST✓ REST✓ REST/Syslog✓ REST/RADIUS
HA / clustering✓ A/P + A/A✓ Cluster✓ A/P + A/A✓ A/P✓ Cluster✓ A/P + Cluster
Compliance reporting✓ Partial✓ Partial✓ Partial✓ Full✓ Full✓ Partial
Selection Tip: When evaluating NGFW and ISFW products, always request throughput benchmarks with SSL inspection enabled and IPS signatures active. Vendors commonly publish "maximum throughput" figures that reflect performance with all security features disabled — real-world performance with full inspection enabled is typically 30–60% lower than the headline figure.