How does subnetting a flat office VLAN create an interior chokepoint against an intruder, and what does that new hop cost?
answer
- the mask decides, not the diagram
- gateway handoff is the chokepoint
- a hop is not a filter
- one-armed means twice over one link
- every default flow becomes a ticket
basics
~20 sSplitting one subnet into several forces traffic between them to a default gateway, and a policy applied at that routed hop is the first thing an intruder's lateral movement must cross. The cost is hairpinned traffic, added latency, a new failure domain and full re-addressing.
solid answer
~50 sIn a flat VLAN there is no interior enforcement point to configure, because nothing between two hosts is doing layer-3 forwarding. Subnetting changes that: once the populations sit behind different masks, every crossing goes to a gateway, and a policy applied there is a chokepoint an intruder has to pass. The critical caveat is that VLANs alone do not filter - if the core routes between the new subnets with no policy, you have bought a hop and no denial. The bill is real: flows that used to stay on a switch backplane now traverse a device link (twice, on a one-armed design), pick up latency, and depend on a box that must be redundant or it becomes the reason the office stops working. Behind that sit DHCP scopes, statically addressed printers, monitoring targets and an exception list for every flow that used to just work.
go deeper
Know that a host uses its default gateway only for destinations outside its own subnet, and that this is why different subnets are what create an inspection point.
Be able to separate the two halves cleanly - a routed hop and a policy applied at that hop - and name at least three concrete costs of inserting one into a working office.
Show you choose the boundary by which crossings you want to police, so the device stays small, and that you plan the exception queue and failure posture before enforcement day.
Frame the tradeoff as an owned budget: the cheapest boundary is the one drawn where traffic is thinnest, and each finer cut buys containment with capacity, latency and a permanent review burden.
## The lever is the addressing, not the diagram A zone drawn on a diagram enforces nothing. What decides whether an interior flow meets a policy is arithmetic done by the sending host: it compares the destination address to its own address and mask, and if the destination is local it sends the frame directly. Only when the destination falls outside the sender's subnet does the host hand the frame to its default gateway. **That handoff is the only thing that manufactures an interior chokepoint.** Subnetting is therefore not paperwork before the real work - it is the mechanism. ## Chokepoint = routed hop + policy applied there Two halves, and estates routinely deliver only the first: 1. **The routed hop.** Different subnets for the populations you want to separate, so traffic between them must be forwarded at layer 3. 2. **A policy at that hop.** A filtering layer-3 interface, or a firewall the routed path actually traverses. If the core switch routes between the two new subnets at line rate with nothing applied, you have separated broadcast domains and created an extra hop. An intruder crosses it without being asked a question, and there is still no log entry. Interviewers probe exactly here, because `we segmented the network` is said far more often than a deny was ever configured. There is a second trap: a policy that sits somewhere the traffic does not go. If the gateway for both subnets is the same core switch and the firewall hangs off it as a separate device, the routing has to be arranged so crossings are actually delivered to that device. Otherwise the rule base is correct, complete, and never consulted. ## What the hop costs **Capacity.** Traffic that was forwarded inside a switch now leaves it. On a one-armed design, where the filtering device has a single trunked link, every east-west flow enters and leaves on that same link, so it consumes twice its own bandwidth there. File copies, image deployments and backup traffic that were invisible to any budget are now a line on a datasheet. **Latency.** A routed and inspected hop is measured in tens of microseconds to low milliseconds instead of switch-backplane time. Most users never notice; bulk transfers and chatty file-share workloads do, and those complaints arrive on the network team's desk. **Availability.** The new gateway is on the path of internal work that used to survive anything short of a switch failure. That forces a redundant pair, doubling the purchase, and forces a decision about failure posture: if the device dies, does the office keep working or does the boundary hold? **Re-addressing labour.** New DHCP scopes and relay configuration, statically addressed printers and building appliances, hard-coded addresses inside applications, monitoring and backup targets, and access lists elsewhere that named the old range. **The exception list.** Every flow that used to work by default now needs a decision. The first weeks after enforcement are a queue of tickets, and each one either becomes a permit or becomes an argument with a business owner. ## The honest scope answer Because the price scales with how much traffic crosses a boundary, the design question is not `how many subnets` but `which crossings do I want to police`. Keep populations that talk constantly on the same side of the boundary; put the boundary where the flows are few, well understood and worth inspecting. That keeps the device you must buy small, and it is the difference between a boundary that ships and one that stalls in a capacity review.
- An estate splits into thirty subnets but complains nothing is being denied. What do you check first?Whether any policy is applied where the routing happens. Thirty subnets with a core switch routing freely between them is thirty broadcast domains and one open network. Check the layer-3 interfaces for an access list, and check that inter-subnet traffic is actually delivered to the filtering device rather than short-cutting around it.
- How would you choose where to draw the first boundary in a flat campus?Where the crossing traffic is small, well understood and meaningful - typically between the office floor and the server population, or around a population with a clear owner such as building systems. That keeps the device you must size small and the exception list short, which is what gets the first boundary funded and actually enforced.
- What is the argument for filtering at the gateway interface instead of hauling traffic to a separate device?Cost and latency. A filtering layer-3 interface on kit you already own keeps the traffic on the same platform and avoids a hairpin, at the price of a coarser policy and weaker logging. A separate device gives richer inspection and evidence, but you must buy it, size it for east-west volume and make it redundant.
saying these in an interview costs you the question
- Claims VLANs by themselves separate traffic
- Assumes a rule base is enforced without checking the path
- Ignores hairpinned east-west volume on the new hop
- Forgets statically addressed printers and appliances
- Treats the exception list as a one-off task