IP transport and segmentation
List the endpoints, transports and connection direction your integration requires. Use that list to define routing, segmentation and firewall rules.
Sources and scopeSource record 25 August 2026
Technical source record: 25 August 2026. Check the linked documentation for current product requirements.
Design baseline, not a site addressing plan, firewall rule set, or performance validation.
On this page
Overview#
Ethernet and IP provide reachability, not application interoperability or trust. IEEE 802.3 defines Ethernet layers; IEEE 802.1Q covers bridges and VLANs. IPv6 is standardised in RFC 8200, TCP in RFC 9293, and UDP in RFC 768.1234
Layer contract#
| Layer | Record explicitly | Common false inference |
|---|---|---|
| Ethernet | link speed/duplex, VLAN, MTU, PoE, redundancy, multicast treatment | same VLAN means trusted |
| IP | v4/v6 addresses, prefix, routes, gateways, fragmentation policy, NAT | IP address is device identity |
| Transport | TCP/UDP, local/remote ports, connection direction, keepalive, timeout | TCP ACK means application completed |
| Application | protocol edition/profile, framing, correlation, authorisation | TLS alone makes commands safe |
TCP is a byte stream: parsers must handle partial and coalesced messages, bound lengths, and implement application correlation. UDP preserves datagram boundaries but not delivery, ordering, uniqueness, or path MTU success; application retry and duplicate rules are essential. Neither transport authenticates a peer.
IPv4 and IPv6#
Maintain policy parity. An IPv4 only firewall rule doesn't constrain IPv6, and link local IPv6 may remain active even when no global address was planned. Inventory all addresses, extension header policy, multicast dependencies, neighbour discovery exposure, DNS records, default routes, and management binding. Don't disable IPv6 casually when the product or secure protocol uses it; constrain and monitor it deliberately.
NAT isn't an authorisation control. It can break protocols that advertise embedded addresses, use multicast/broadcast, accept inbound callbacks, or bind security identity to an endpoint name. Prefer routed, policy controlled zones and protocol aware configuration over undocumented address translation.
Segmentation pattern#
Create zones from consequence and administration, not vendor alone: endpoints, controllers/servers, management, monitoring, identity/time, operator clients, and third party/remote service. Define conduits as exact source, destination, direction, protocol, port, initiating role, rate, and maintenance window. Default deny unused east west and management access; log policy changes and denials at a sustainable rate.
VLANs provide logical separation inside a bridge domain but require routed enforcement to become a security boundary. QoS, multicast snooping/queriers, redundancy, and security inspection must preserve alarm latency, media bandwidth, and industrial real time requirements. Validate failover and congestion on an isolated representative design.
Failure and observation#
Instrument link transitions, address/route change, duplicate address, neighbour/ARP churn, connection failure, RTT/loss, retransmission, UDP sequence gaps, MTU/fragmentation failure, multicast membership, firewall deny, and application health separately. A ping response is neither application health nor identity proof.
Validate segmentation, failover, congestion, MTU, multicast, and packet filter behaviour against the authorised target network and recovery plan.