Home/Network Security

Network security

Who may connect, what may pass, what gets recorded.

Network security in plain terms first, technical detail second. The same principles apply whether the network serves a household or an organisation.

  • Internal and external network protection
  • Wi-Fi, router and gateway security
  • Traffic management, policy and monitoring
Network security in plain termsThe public internet on one side, your network and devices on the other, and a boundary between them that decides who may connect, what may pass and what is recorded.OUTSIDETHE PUBLICINTERNETTHE BOUNDARYWho may connectWhat may passWhat is recordedINSIDEYOUR NETWORKAND DEVICES
Outside, boundary, inside — the whole idea in one picture

In plain English

Three questions, asked continuously.

Strip away the terminology and network security comes down to a short list. Every product and policy below is a way of answering one of these.

Who may connect?

Which devices and people are allowed onto the network, and what they can reach once they are on it.

What may pass?

Which traffic is permitted across the boundary, in both directions, and which is stopped.

What gets recorded?

Which decisions are kept, so activity can be reviewed and a rule corrected if it was wrong.

Internal network security

What happens between the devices you already trust.

Most networks are flat by default: everything connected can reach everything else. That is convenient right up until one device is compromised, at which point convenience becomes the problem.

Internal security defines which zones may reach which. A camera does not need access to a file server; a visitor's laptop does not need either. Available segmentation depends on your architecture.

Internal network zonesA firewall policy sits above three network zones: a main network with full access, a smart device zone with limited access, and an isolated guest zone. Traffic between zones follows the configured policy.MAIN NETWORKFULL ACCESSSMART DEVICESLIMITED ACCESSGUEST ACCESSISOLATEDFirewall policyTRAFFIC BETWEEN ZONES FOLLOWS THE POLICY YOU SET
Zones and the access permitted between them

External network protection

The boundary between your network and everyone else's.

Any network connected to the internet receives steady background traffic it never asked for: scans, probes and connection attempts. Filtering that at the boundary is the baseline.

Outbound traffic deserves the same attention. Connections leaving the network are measured against policy, which is how activity that does not fit the usual pattern becomes visible.

External network protectionConnection attempts approach the network from outside. Unsolicited inbound traffic, port scans and unknown hosts are stopped at the perimeter, while requested traffic such as a web page, a video stream and a software update is allowed through.YOUR NETWORKPERIMETER POLICY APPLIEDUNSOLICITED INBOUNDPORT SCANUNKNOWN HOSTREQUESTED PAGEVIDEO STREAMSOFTWARE UPDATEUNWANTED CONNECTIONEXTERNAL NETWORK ACTIVITY
Inbound attempts filtered, outbound activity measured

Wi-Fi, routers and gateways

The equipment everything else depends on.

The router is the one device with a permanent connection to the outside, which makes its configuration disproportionately important. Administrative access, remote management and network separation are the settings that matter most and get looked at least.

Wi-Fi separation between main, guest and device networks limits how far a problem can travel. Options depend on your equipment.

Wi-Fi network separationThree Wi-Fi networks side by side: a main network for trusted household devices, a guest network kept off the main network, and a separate device network for cameras, speakers and appliances. Separation options depend on router and service configuration.Main Wi-FiHousehold devicesyou trustPOLICY APPLIEDGuest Wi-FiVisitors, kept offthe main networkPOLICY APPLIEDDevice networkCameras, speakers,appliancesPOLICY APPLIEDONE NETWORK, SEPARATED SENSIBLYSEPARATION OPTIONS DEPEND ON YOUR ROUTER AND SERVICE CONFIGURATION
Main, guest and device networks kept apart

The technical layer

For readers who want the specifics.

Same subject, more detail. Capabilities below depend on the service and architecture selected.

Firewall policies

Rule sets defining permitted traffic in both directions, applied consistently across protected networks.

  • Inbound connection filtering
  • Outbound policy checks
  • Zone-to-zone rules

Traffic management

Visibility of what is crossing the network, with controls over how different kinds of traffic are handled.

  • Connection-level visibility
  • Application-aware controls in NGFW
  • Consistent enforcement

Threat monitoring

Continuous observation with events recorded for review rather than discarded.

  • Automated monitoring
  • Recorded policy actions
  • Reporting depth varies by plan

Segmentation

Structured separation so access follows the shape of the household or organisation.

  • Guest and device zones
  • Operational separation
  • Depends on architecture

Secure connectivity

Encrypted access back to a protected network for people working away from it.

  • VPN and secure access options
  • Policy applied to remote sessions
  • Availability varies by configuration

Network visibility

A current picture of what is connected and how it behaves — usually the first real benefit.

  • Device and connection visibility
  • Behaviour compared to policy
  • Basis for informed changes

FAQ

Network security questions.

What does network security actually mean?

Deciding who may connect to a network, what may pass across it, and keeping a record of both. Everything else — firewalls, segmentation, monitoring, secure access — is a way of implementing those three decisions.

Is network security the same as antivirus?

No. Antivirus protects an individual device from software running on it. Network security governs traffic crossing the network, which covers devices that cannot run protective software at all. They address different problems.

What is the difference between internal and external protection?

External protection concerns traffic crossing the boundary between your network and the internet. Internal protection concerns how devices inside the network reach each other. A flat internal network means one compromised device can reach everything else.

Do home networks really need this?

A home network carries personal files, financial logins, cameras and conversations, usually with no administrator. The scale is smaller than a business network; the value of what crosses it often is not.

What does 'network visibility' mean in practice?

Being able to see what is connected and what it is doing. Most networks accumulate devices nobody remembers adding, and visibility is what turns that into something you can make decisions about.

Can secure remote access be included?

Where the configuration supports it, encrypted connections back to a protected network can be part of the service. Availability varies by plan and architecture.

Next step

Start with the network, wherever it is.

Home, office or both. Describe what you are protecting and we will explain what fits.