Host-based micro-segmentation approach to restrict traffic within the same network?
Hi everyone
I want to know whether a host-based micro-segmentation approach can restrict the communication channel between hosts residing on the same network. Without any additional infrastructure like FortiSwitch and FortiAP.
"Micro-segmentation Approaches:
There are three primary approaches to micro-segmentation security, and they are categorized based on where the implementation is taking place: network-based, hypervisor-based, and host-based.
1. Network-based
Network-based microsegmentation involves choosing who or what can enter different segments of the network. One benefit is it is straightforward to administer, making it less work-intensive for administrators. However, network-based segmentation is essentially very similar to traditional segmentation, and if you end up with very large segments, it can be difficult and costly to administer security controls.
2. Hypervisor-based
With a hypervisor, you have software or hardware that makes and runs virtual machines. Hypervisor-based microsegmentation directs all of your traffic through the hypervisor, giving you the ability to monitor and manage it. In many cases, this is a convenient choice because you can often do this with your existing firewalls and move security policies from one hypervisor to another.
On the downside, a hypervisor-based approach does not work well within cloud deployments or with bare metal, container, or physical workloads.
3. Host-based
Host-based micro-segmentation depends on positioning agents within each endpoint. With this kind of architecture, a central manager has visibility of all data, processes, software, communications on the network, and potential vulnerabilities. However, to achieve this visibility, the administrator has to install an agent on each and every host. This could be time-consuming for both the administrator and end-users."
Please find the link to understand more about micro-segmentation
https://www.fortinet.com/resources/cyberglossary/microsegmentation
So to communicate, the host residing on the same subnet needs to traverse the FortiGate Firewall and pass through the policy with the security scan.
Kind regards,
Bijay Prakash Ghising
