Stop Lateral Movement in Hours, Not Months
Quickly deploy microsegmentation across every workload with identity-based policy, not network architecture. No firewall rewrites, no VLAN redesigns, and no blind spots.
Watch the Demo
Watch Jerome Mills, Sales Engineer at NetFoundry, demonstrate how to simplify microsegmentation across multi-cloud environments like AWS, Azure, and GCP using the NetFoundry Zero Trust platform. Learn how to eliminate complex firewall rules, overcome network drift, and instantly secure application connectivity with software-based, outbound-only connections.
Legacy Segmentation Takes Weeks to Months.
Attackers Take Minutes
One foothold becomes a full intrusion
However the attacker gets in, that single foothold becomes a full intrusion by moving system to system until it reaches the assets that matter. Breakout now happens in minutes, often without malware, so perimeter detection sees nothing unusual — and the legacy answer, VLANs and firewall rules, is too slow to deploy and too brittle to change to contain it.
- Boundaries defined by IP address and network location — policy drifts as infrastructure changes
- 100s to 1000s of rules across tools, teams, and firewalls, and roughly two weeks to make any single change
- VLAN redesigns and firewall reviews that slow every new application, vendor, or workload
- Visibility limited to IP and port — hard to trace activity by identity across boundaries
- Every flow must be discovered and defined up front before segmentation can be deployed
“We have tons of policies/rules across multiple tools, firewalls, and other infrastructure to allow communication between workloads. It takes two weeks to make any change.”CTO — National Telco, Postal, and Logistics Operator
The All-or-Nothing Trap
Months of flow discovery and dependency analysis pass before your first workload is contained, and one missed flow can break a production application. Enforcement slips quarter after quarter while the full risk stays in place.
Segment by Identity, Without Touching Firewalls or Networks
NetFoundry replaces IP-based segmentation with identity-based segmentation. Access is granted per identity and service, not per subnet, and you define it as policy, change it in seconds, and start segmenting without discovering and defining every flow before you deploy. Three things make that practical:
Segment at the right level, per service
Every grant is scoped to a specific identity reaching a specific service. A workload reaches only the services policy names — nothing else is routable, and there is no subnet-wide access to exploit.
Apply segmentation at the host or gateway through a connector, across the network, or in the application through the SDK. Start at whichever level is easiest for each workload, and extend over time.
Discovery and audit, by identity
Turn on discovery when you want it, run policy in passive mode before you enforce, and visualize flows first. Discovery runs continuously, never as a project you must finish first.
Every connection is attributed to a named identity and service, not an IP and port, across microsegmentation, Zero Trust, and remote access in a single view.
One model, default deny, instant change
Nothing connects unless policy explicitly authorizes it. Every workload — human, machine, and AI — carries a cryptographic identity, and connections are outbound-only, so there are no inbound ports to scan.
Adjust a boundary with a policy update, not a firewall ticket or a VLAN redesign. The same model, control, and audit apply across every environment, giving one point of governance instead of a tool per silo.
Under the hood, mutual authentication with X.509 certificates verifies identity and evaluates policy before any routable path exists — so the default is deny, the target is invisible until authorized, and policy no longer drifts as infrastructure changes.
3,000 companies trust NetFoundry — including 8 of the 10 largest US banks and 2 of the 5 largest US companies.
Four Moves to Contained, Low-Maintenance Segmentation
No flow-mapping project, no VLAN redesign, no firewall tickets — each move is policy you apply on top of the infrastructure you already run.
Define access by identity, not network
Each workload gets a cryptographic identity bound to it. Policy defines which identity may reach which service, independent of IP address, subnet, or location. Nothing to map first.
Authenticate before any path exists
Mutual authentication with X.509 certificates establishes an encrypted, outbound-only conduit only after identity and policy are verified.
Enforce least privilege east-west
Authorized identities reach only the specific services policy permits — nothing more. Lateral movement to anything else is structurally impossible, regardless of the network.
Change in seconds, audit by identity
Adjust a boundary by updating policy — no firewall changes, no VLAN edits, no two-week window. Every connection is logged by identity and service for compliance.
Want the architecture in depth — the controller, the identity model, and policy enforcement? Explore the platform →
One Model for Microsegmentation, Zero Trust, and Remote Access
Most teams run microsegmentation on one stack, Zero Trust on another, and remote access on a third — each with its own console, its own policy language, and blind spots at every border between them. NetFoundry runs all three on one identity-based model, so east-west and north-south traffic are governed the same way.
Microsegmentation
Same site. Contain lateral movement between workloads on the network you already run.
Zero Trust
Across site, admin, or technology borders. A server or API stays unreachable from the network and reachable only by authorized identities.
Secure Remote Access
Remote admins — human or machine — get least-privileged access to a single service, not VPN-level access to the whole network.
For the CISO, that means one place to define policy and one audit trail across all three motions, rather than reconciling firewalls, NAC, VPN, ZTNA, and separate microsegmentation tools. You consolidate silos instead of adding one, and retire VPNs, firewall rule sprawl, and point tools as workloads migrate.
Deploy in an Afternoon, Not a Quarter
Legacy segmentation is a network project: map every flow, redesign VLANs, and open a ticket for each rule change. NetFoundry is policy you stand up on top of the infrastructure you already run. You put the fire out first — contain your highest-value workload today, then extend across the estate at your own pace.
Secure one workload
Spin up protection for a single critical workload in minutes — as code, with no firewall changes, no integrations, and nothing else in your environment disrupted. Get started without waiting to map your entire estate.
And your whole estate
Apply one identity-first policy model across cloud, datacenter, OT, AI, and third-party workloads — replacing a tangle of per-environment tools and control planes with a single way to define, change, and audit segmentation.
Legacy segmentation
- Discover and map every flow before you can deploy
- Redesign VLANs and re-architect subnets
- ~2 weeks per change across teams and firewalls
- A different tool and control plane per environment
- Rip-and-replace risk to roll anything back
NetFoundry
- Start segmenting Day 1 — no flow-mapping project first
- Runs on existing infrastructure, untouched
- Change a boundary in seconds with a policy update
- One policy model across every environment
- Add or revoke a segment incrementally, instantly
One Way to Segment. Every Environment Covered.
With legacy microsegmentation, every environment and architecture demands its own approach — complex, hard-to-change rules enforced at the workload, host, hypervisor, and network layers. A typical enterprise ends up running several different tools and control planes for segmentation, with no uniform policy and no single view across them. NetFoundry applies one identity-first policy model everywhere — including the workloads traditional tools can’t reach.
Contain agents, models, and tools
Give AI agents, MCP servers, and LLMs sovereign identities with policy-scoped access — so a compromised agent can only reach what it is explicitly authorized to reach.
East-west control across hybrid infrastructure
Segment apps, VMs, containers, and Kubernetes workloads by identity across clouds and on-prem — with no changes to your infrastructure as code (IaC) or virtualization platforms, and no per-cloud firewall rules to maintain.
Reach devices agents can’t
Bring least-privilege segmentation to OT, IoT, and legacy or unmanaged devices using clientless, host, or gateway options — aligned to IEC 62443 zones and conduits.
Segment partner and vendor access
Replace broad VPN tunnels with service-level access scoped to a single partner identity — granted and revoked instantly, with a full audit trail.
Borderless and universal — one identity model, reached through connectors for applications, devices, gateways, and firewalls, including turning an existing firewall into a Zero Trust enforcement point rather than ripping it out.
“We moved beyond the perimeter with NetFoundry. It delivers a strictly least-privileged access model that is incredibly easy to deploy. The management console turns what used to be a tangle of firewall rules into a streamlined, visual command center.”
Viktor Szabo, Deputy CTO, Ominimo
Replace NSX DFW with Segmentation That Survives the VMware Exit
NSX Distributed Firewall enforces inside the ESXi kernel, so its policy evaporates the moment a workload leaves vSphere. Migrations to Nutanix, Proxmox, or the cloud run in waves over 12 to 36 months, with application tiers split across two platforms the whole time — and the destination platform has no NSX-equivalent distributed firewall to carry the policy forward.
Segmentation that moves with the workload
NetFoundry attaches policy to the workload identity, not the vNIC or the hypervisor, so each migration wave carries its policy with it. You keep segmentation continuous across both platforms for the entire migration window, instead of leaving migrated workloads unsegmented until a firewall project catches up.
Mirror your existing DFW intent as identity-to-service policy, run it in passive mode, and turn on enforcement when you are ready — no flow-mapping project to begin. When the migration finishes, the same model still covers those workloads, and it extends to the cloud, OT, and AI estates NSX never reached.
- Policy bound to workload identity, not the vNIC — it never depends on vSphere
- One identity-to-service model spans both platforms for the whole migration
- Gateways front legacy and end-of-life workloads that cannot take an agent
- No re-IP, VLAN redesign, or firewall rule build-out to segment the new platform
- A permanent segmentation layer after cutover — not a project that restarts from zero
During the migration
Overlay gateways front both platforms. DFW intent is mirrored as identity-to-service policy in passive mode, then enforced — so app tiers split across vSphere and the new platform stay segmented as VMs move in waves.
Steady state
Server connectors run on the tiers themselves and DFW retires for good — the same policy objects, now with no hypervisor dependency, extended across cloud, OT, and AI.
Smaller Blast Radius. Less Operational Drag.
Contained blast radius
A compromised identity reaches only what policy allows. One foothold stays one foothold instead of becoming a network-wide intrusion.
Invisible east-west and north-south surface
No routable path exists until identity and policy authorize it. There’s nothing to scan, discover, or exploit between workloads.
Policy changes in seconds, not sprints
Tighten or extend boundaries with a policy update. No change-control cycle, no firewall rules, no VLAN redesign.
Visibility by identity, not IP
See which identity reached which service, across every environment — meaningful, auditable insight instead of IP-and-port guesswork.
Reduced compliance scope
Identity-based isolation shrinks the systems in scope for audits and maps cleanly to segmentation mandates in PCI-DSS, IEC 62443, and NIST 800-207.
No network redesign or downtime
Works across existing infrastructure. Deploy incrementally, add segments progressively, and leave VLANs and underlay routing untouched.
Built for Regulated, Segmented, and Insurable Environments.
Network segmentation is moving from a best practice to a requirement across frameworks and cyber-insurance criteria. Underwriters increasingly ask for network segmentation and least-privilege access as a condition of coverage, and identity-based segmentation gives you a clean, auditable way to demonstrate both. NetFoundry maps identity-based segmentation directly to those mandates — and runs it at the scale critical infrastructure demands.
Built by the creators and maintainers of OpenZiti, the world’s most-used open-source zero-trust networking platform.
Microsegmentation Questions
What is microsegmentation?
Microsegmentation is the practice of isolating individual workloads — rather than whole network segments — so that a compromised system cannot reach anything beyond what policy explicitly allows. Traditional segmentation isolates whole subnets; microsegmentation isolates down to the individual workload or service. NetFoundry does this with cryptographic identity instead of IP addresses or network location.
How is microsegmentation different from VLANs and firewall rules?
VLANs and firewall rules define access by where a workload sits on the network, so policy drifts as infrastructure changes. Identity-based microsegmentation defines access by cryptographic identity instead, so a workload reaches only the services policy names — regardless of its IP address, subnet, or location.
How is microsegmentation related to Zero Trust?
Microsegmentation is how Zero Trust is enforced east-west, between workloads. NetFoundry applies one identity-based model across all three motions — east-west microsegmentation, north-south Zero Trust, and secure remote access — so the same policy, visibility, and audit cover traffic in every direction.
Does microsegmentation require managed switches or a network redesign?
No. NetFoundry’s microsegmentation runs as a policy layer on top of existing infrastructure, with no VLAN redesign, no managed-switch dependency, and no firewall rule changes. A single workload can be protected in minutes, and the rest of the environment is left untouched.
Can microsegmentation work on OT and IoT devices with unmanaged switches?
Yes. Flat OT networks typically run on unmanaged switches, which gives VLAN- or switch-based segmentation nothing to enforce against. Because NetFoundry segments by identity instead of network position, it brings least-privilege zones to OT, IoT, and legacy devices with no change to the underlying switching infrastructure.
How does NetFoundry replace VMware NSX (DFW) segmentation during a migration?
NSX Distributed Firewall enforces inside the ESXi kernel, so its policy does not follow a workload once it leaves vSphere. NetFoundry attaches policy to the workload identity instead of the vNIC, keeping segmentation continuous across both platforms throughout a migration to Nutanix, Proxmox, or the cloud. Mirror existing DFW intent as identity-to-service policy, run it in passive mode, and enforce when ready; the same model remains after cutover and extends to cloud, OT, and AI workloads NSX never covered.
How long does it take to deploy microsegmentation?
NetFoundry customers typically protect a single critical workload in an afternoon, because there is no flow-mapping project or VLAN redesign required before deployment starts. Rollout across the estate then proceeds incrementally, at whatever pace the organization chooses.
Does microsegmentation help with compliance and cyber-insurance?
Yes. NetFoundry’s identity-based microsegmentation maps directly to segmentation requirements in frameworks including PCI-DSS, IEC 62443, NIST 800-207, and NIST 800-171, and it narrows audit scope by isolating sensitive workloads at the identity level rather than the network level. Because cyber-insurance underwriters increasingly require segmentation and least-privilege access, the same controls and per-identity audit trail help you demonstrate those requirements at renewal.
Contain Breaches. Deploy Quicker. Cut Costs.
See how identity-first microsegmentation stops lateral movement across your cloud, datacenter, OT, AI, and third-party environments — without a single network change.
- Average eCrime breakout time from initial access to lateral movement, and share of malware-free detections. CrowdStrike, 2026 Global Threat Report (Feb. 2026). crowdstrike.com