skip to content

The Traffic Inside

Most flows in a real estate never leave it, so a perimeter filter inspects the minority and none of the movement after a compromise. Interviewers probe where you would put a filter at all.

on this pageshow

questions

4

An intruder pivots between two PCs on one flat office VLAN - why does the perimeter firewall log nothing, and what would have to change first?

level: juniorimportance: must knowfreq 72%

answer

  1. same subnet, same conversation
  2. the frame never asks the gateway
  3. a control off the path logs nothing
  4. a routed hop is the thing you buy

basics

~20 s

Two hosts in the same subnet talk directly through the switch and never reach the default gateway, so a border firewall is simply not on that path and records nothing. Only splitting them into separately routed subnets puts a device in the way.

solid answer

~40 s

Both PCs sit in one VLAN and one IP subnet, so the sender compares the destination against its own mask, decides it is local, resolves its MAC with ARP and sends the frame straight to it. The frame goes up an access-switch port and back down; it never carries the gateway's MAC, so no routed hop and no firewall ever handles it. A perimeter firewall only forwards or drops what crosses the campus-to-internet path, so its empty log is a topology fact, not a rule gap or a missed detection. Before any device could log that pivot, the two hosts have to be in different subnets with the traffic between them routed through something that applies policy - which means re-addressing plus a device someone has to fund and keep running.

go deeper

for a junior

Be ready to state the rule out loud: a host sends to its default gateway only for destinations outside its own subnet, so same-subnet traffic meets no router and no firewall.

for a middle

Explain the frame path end to end - mask comparison, ARP, MAC-addressed frame, access switch, uplink - and say precisely which device would first see it if the two hosts were in different subnets.

for a senior

Show that you will not respond to an empty border log by tuning the border. Name the change that would create a record, and the re-addressing and hardware it drags behind it.

for a principal

Own the framing that the estate bought edge visibility and got exactly what it paid for. The gap is a design decision that was never funded, not an operations failure to escalate.

## What actually happens on the wire In most campus estates a floor of wall sockets lands in one VLAN and one IP subnet - say `10.20.4.0/22`. When `10.20.4.31` opens a session to `10.20.4.87`, the sending host compares the destination address against its own address and mask, concludes the destination is local, and resolves the destination's MAC address with ARP. It then addresses the frame to that MAC directly. The frame travels up the access-switch port, possibly across a wiring-closet uplink to a second access switch, and back down to the target. It never carries the default gateway's MAC address, which means no router, no layer-3 interface and no firewall is ever handed the packet. A host consults its default gateway only for destinations **outside** its own subnet. That single rule is what decides whether an interior flow meets an enforcement point, and in a flat office VLAN the answer is that it does not. ## Why the border sees nothing A perimeter firewall is a device positioned on the path between the campus and the internet. It logs what it forwards and what it drops. Traffic that never leaves the subnet is never offered to it. There is no rule it could have carried, no signature it could have matched, no log line it could have emitted. Silence here is not a tuning failure, a licensing gap or an analyst missing something - it is a statement about where the device stands. This is the direction-of-claim mistake that gets made in review rooms: an empty border log proves that traffic did not cross the border. It proves nothing whatsoever about traffic that had no reason to. ## Why an intruder gets this for free An intruder who has a foothold on one office PC - a workstation on the same floor as the one they want next - is not evading anything. There is nothing in the path to evade. Credential reuse, a file share, a remote-management port, a scan of the local range: all of it happens between two hosts that are layer-2 adjacent. The controls the organisation bought sit at the edge of a bubble the intruder is already inside. Switches forward frames at line rate in hardware; they are not built to journal every conversation, and nothing in the default configuration produces a per-flow record for intra-subnet traffic. ## What it would take to produce a record The only thing that manufactures an interior chokepoint is the addressing. Put the two populations in different IP subnets, and traffic between them must go to a default gateway; put policy on that gateway - a filtering layer-3 interface or a firewall the routed path traverses - and now every crossing is inspected, permitted or denied, and logged. That is a real bill, and it is why so many estates have not done it: | What you must add | What it costs | |---|---| | A second subnet and re-addressing | DHCP scopes, statically addressed printers and appliances, host firewall rules, monitoring targets | | A routed hop between them | Traffic that stayed on a switch backplane now crosses a device link, twice on a one-armed design | | A device that filters it | Purchase, sizing, depreciation, and a redundant partner so an interior outage does not stop the office | | An exception list | Every flow that used to work and now has to be explicitly permitted | ## The honest interview answer Say the mechanism first (same subnet means no routed hop, so no device in the path), then the consequence (the border log is empty for a truthful reason), then the price (a record exists only where you have paid to put something in the path). A candidate who says the firewall *missed* it, or that the rules need reviewing, has the model backwards and will size the wrong solution.

  • If both PCs are in the same subnet but on different access switches, does that change your answer?
    No. The frame still travels switch to switch across the closet uplink and is still addressed to the destination host's MAC, not the gateway's. Crossing more switches adds hops but no routed hop, so there is still no layer-3 device deciding whether the flow is allowed. Physical distance is not a boundary; the subnet mask is.
  • Does putting the two departments in separate VLANs fix this on its own?
    Only partly. Separate VLANs mean separate subnets, so traffic between them now goes to a gateway - but if the core switch routes between those subnets with no policy applied, you have added a hop, not a filter. The chokepoint exists only where routing happens **and** a policy is enforced there.
  • Your border firewall logs are empty for the whole intrusion window. Is that evidence the intruder was quiet?
    No. It is evidence that nothing crossed the border, which is a different claim. Lateral movement inside one subnet produces no border record whether it is loud or quiet, so the log cannot distinguish the two. Reading silence from an off-path control as reassurance is how estates conclude they were fine.

A guard on the building's front door can tell you everyone who came in off the street, and nothing at all about who walked between two desks on the fourth floor.

saying these in an interview costs you the question

  • Says the firewall missed it or the rules are wrong
  • Treats an empty border log as proof nothing happened
  • Assumes switches log every frame they forward
  • Thinks adding a VLAN by itself filters traffic
  • Believes the intruder evaded the perimeter control

context

open as a page

How does subnetting a flat office VLAN create an interior chokepoint against an intruder, and what does that new hop cost?

level: middleimportance: must knowfreq 58%

basics

~20 s

Splitting one subnet into several forces traffic between them to a default gateway, and a policy applied at that routed hop is the first thing an intruder's lateral movement must cross. The cost is hairpinned traffic, added latency, a new failure domain and full re-addressing.

open as a page

An executive reads empty border firewall logs after an internal intrusion as proof the controls held - how do you answer, and what would have to be in the path before a record could exist?

level: seniorimportance: nice to knowfreq 30%

basics

~20 s

Empty border logs prove only that the traffic did not cross the border. A control that is not on the path produces no evidence in either direction. A record of interior movement exists only once you fund a routed hop and a device that inspects it.

open as a page