Isolated Network Architectures – Red Network and Green Network Deployment
Design and build Red Network, Green Network and air-gapped isolation: segmentation, controlled transit, jump server, PAM, MFA, DLP and SOC visibility.
In organizations holding critical information systems, sensitive data and applications requiring high security, running all systems within the same network infrastructure can create significant security risks. User computers, systems with internet access, management servers, critical applications and systems processing sensitive data all carry different security levels.
SecureSys provides services for designing, building and integrating Red Networks, Green Networks, isolated networks, secure zones, management networks and critical system networks into existing IT infrastructure according to an organization's security requirements.
In isolated network architectures, the core aim is not simply to separate systems into different VLANs. The aim is to reduce the attack surface of critical systems, minimize communication between networks, control data flows, and ensure only authorized users and devices can reach systems requiring high security.
According to the organization's risk level and security requirements, separation can be carried out with different methods such as;
- logical network segmentation,
- physical network separation,
- security zones,
- firewall-controlled segmentation,
- micro segmentation,
- closed-circuit network,
- Air-Gapped Network
and similar approaches.
What Is a Red Network?
A Red Network is the isolated or heavily restricted network zone created within an organization for running critical information systems, sensitive data or applications holding a high security level.
Within a Red Network, the;
- critical application servers,
- systems processing sensitive data,
- critical databases,
- management systems,
- servers requiring special protection for security reasons,
- critical infrastructure components,
- dedicated project environments
can be located.
Access to Red Network systems can be restricted with tighter security policies than the standard user network.
Access can be granted only through defined users, management workstations or secure transit systems.
What Is a Green Network?
A Green Network can be designed as the general corporate network zone where the organization's standard operations run and controlled internet access is provided.
Within this network, the;
- user computers,
- office applications,
- standard business systems,
- printers,
- corporate internet access,
- general user services
can sit.
Rather than systems in the Green Network reaching critical systems on the Red Network directly, access can be provided through controlled transit points in line with security policies.
Separating the Red Network and Green Network
The core aim of a Red and Green Network architecture is to separate systems holding different security levels from one another.
An example architecture:
Internet → NGFW → Green Network → Security Transit Layer → Red Network
In this structure, the aim is that there is no direct, uncontrolled communication between standard user systems with internet access and critical systems.
Where security requirements are higher, the architecture;
Internet → Firewall → Green Network → Internal Firewall → Controlled Transit Zone → Red Network
can be designed in this way.
The Red Network is then placed behind a separate security layer.
Physical Network Separation
In structures requiring high security, VLAN-based logical segmentation alone may not be considered sufficient.
In that case, physically separate;
- switch,
- firewall,
- network interface,
- cabling,
- server,
- management infrastructure
can be used for the Red Network and the Green Network.
Physical network separation helps reduce the dependencies between systems at different security levels.
SecureSys evaluates physical and logical separation options together according to the organization's security requirements.
Logical Network Separation
In structures using the same physical network infrastructure, logical separation can be carried out using VLAN, VRF, firewall zones and access policies.
For example;
Green VLAN → Firewall → Red VLAN
this structure can be built.
But creating VLANs alone does not amount to full isolation. The routing between VLANs, firewall policies, management access and other network dependencies must be controlled together.
Air-Gapped Network – Fully Isolated Network
An Air-Gapped Network architecture can be used for systems requiring very high security.
In the air gap approach, the critical system network is separated physically or architecturally from the internet and from the organization's standard production network.
Example structure:
Corporate Network → Controlled Transfer Area → Air-Gapped Critical System Network
In some structures there may be no direct network connection at all between the critical environment and other networks.
In such environments, dedicated procedures and controlled transfer mechanisms must be established for moving data.
Air-gapped architectures can be evaluated particularly for highly sensitive systems, critical infrastructure and working environments requiring special security.
Closed-Circuit Network Deployment
A closed-circuit network infrastructure can be built for systems that do not need internet access.
On closed-circuit networks, systems can communicate only with devices inside their own security zone.
This approach can be used for;
- critical management systems,
- production environments,
- test laboratories,
- sensitive data processing systems,
- dedicated project environments
and similar cases.
SecureSys can design a closed-circuit network architecture according to the organization's access and data transfer needs.
Controlled Security Transit Layer
Where communication between the Red Network and the Green Network cannot be blocked entirely, a controlled transit layer can be built between the two security zones.
In this layer, security technologies such as;
- Next Generation Firewall,
- Jump Server,
- Bastion Host,
- PAM,
- MFA,
- Proxy,
- Secure Gateway,
- DLP,
- Malware Analysis,
- SIEM,
- SOC
can be used as required.
The aim is that all access and data transfers pass through defined security points rather than an uncontrolled connection being created between the networks.
Jump Server and Bastion Host
Granting direct management access to critical systems from user computers can create risk.
A Jump Server / Bastion Host can be used instead, within the Red Network or in the secure transit zone.
Example access model:
Administrator → MFA → PAM → Jump Server → Critical System
With this approach, access to critical systems can be carried out from a central point and users' direct RDP, SSH or similar management connections can be restricted.
Privileged Access Control with PAM
Administrator accounts reaching systems within the Red Network can hold high privileges.
Privileged Access Management solutions can therefore be used.
With PAM infrastructure, controls such as;
- central management of privileged accounts,
- password vaulting,
- access approval,
- session recording,
- tracking of authorized users,
- time-limited access
can be applied.
Strong Authentication with MFA
Granting access to critical networks with a username and password alone may not be enough.
In isolated network architectures, SecureSys can carry out integrations using Multi-Factor Authentication where required to improve access security.
A Separate Active Directory for the Red Network
In some environments with high security requirements, having Red Network systems depend on the standard corporate Active Directory structure may not be desirable.
In that case, a separate;
- Domain Controller,
- DNS,
- user accounts,
- administrator accounts,
- Group Policy
infrastructure can be built for the Red Network.
This approach can reduce the dependency between the critical environment and the standard corporate identity infrastructure.
A Separate Management Infrastructure for the Red Network
In structures requiring high security, a separate management network can be built for managing the systems within the Red Network.
Example:
Admin Workstation → Management Network → Jump Server → Red Network
Standard user computers can then be prevented from reaching the management interfaces of critical systems.
Secure Management Workstations
Dedicated management workstations separated from standard user computers can be built for critical system administrators.
On these systems;
- internet access can be restricted,
- application installation can be controlled,
- USB use can be restricted,
- EDR/XDR can be used,
- user privileges can be reduced,
- management access can be logged.
This approach helps reduce the risk of privileged accounts being exposed to attack.
Red Network and Firewall Security
Inbound and outbound traffic to the Red Network can be controlled with firewall policies.
A Default Deny / Least Privilege approach can be applied in the policies.
Only the;
- source IP,
- destination IP,
- port,
- protocol,
- application,
- user
access required by business processes can be permitted.
By blocking unnecessary inter-network communication, the aim is to reduce the attack surface of the critical environment.
Micro Segmentation
Allowing all systems within the Red Network unlimited access to one another can also create security risk.
Where required, the Red Network can therefore be divided internally into smaller security segments.
For example:
Application Zone → Database Zone → Management Zone → Backup Zone
This approach helps make it harder for an attacker who compromises one system to carry out lateral movement to other critical systems.
One-Way Data Flow
In some critical environments, only data transfer in a defined direction may be permitted rather than two-way communication between two networks.
According to the security requirement, one-way data transfer architectures or Data Diode technologies can be evaluated.
For example, monitoring or log data may need to be exported from critical systems while no connection is granted from the external network into the critical system.
Architectures of this kind must be designed separately in line with the organization's security requirements and the technologies in use.
Controlled File Transfer Area
When file transfer is needed between the Red Network and other networks, users going directly to USB or a network share can create serious security risk.
A controlled transfer area can be built instead.
Example:
Green Network → File Transfer Area → Security Controls → Red Network
The files transferred can be passed through security controls such as;
- antivirus,
- sandbox,
- malware analysis,
- DLP,
- file type check,
- hash check
as required.
USB and Removable Media Control
In fully isolated networks, removable media may have to be used for data transfer.
But USB drives can be one of the significant routes for carrying malware into isolated systems.
Security procedures such as;
- using only authorized media,
- keeping a media inventory,
- malware scanning,
- device control,
- keeping transfer records
can therefore be applied.
Red Network and DLP Integration
Moving data out of a critical network must be controlled.
With Data Loss Prevention solutions, the aim can be to detect or block sensitive data being moved out without authorization over the;
- e-mail,
- web,
- USB,
- file transfer
channels.
Red Network and SIEM Integration
Building an isolated network should not mean removing visibility.
Security logs from systems within the Red Network such as the;
- firewall,
- server,
- Active Directory,
- database,
- endpoint,
- network devices
can be forwarded to the central SIEM infrastructure in a controlled way.
Depending on the architecture, log forwarding can be carried out over a secure gateway or one-way data transfer mechanisms.
Red Network and SOC Monitoring
Having the SOC follow the security events generated by critical systems can help detect attacks early.
Within the SecureSys SOC service, security events from systems inside the Red Network can be analyzed in suitable architectures.
Isolation and security visibility can then be provided together.
Endpoint Security with EDR/XDR
Network isolation alone does not replace endpoint security.
EDR/XDR technologies can be used on supported server and client systems within the Red Network.
These systems can help detect attack behavior such as;
- malware,
- ransomware,
- suspicious process,
- credential theft,
- lateral movement
and similar activity.
Isolated Backup Network
Backup systems being in continuous and uncontrolled communication with the production network can mean the backups are affected in a ransomware attack too.
A separate Backup Network / Backup VLAN / Isolated Backup Network can therefore be built.
In more critical environments, Air-Gapped Backup or Cold Backup models in which backup copies are separated entirely from the production environment can be applied.
Red Network and Disaster Recovery
When designing the Disaster Recovery environments of critical systems, the isolation principles must be preserved in the DR location too.
Moving a system that runs within the Red Network in the production environment onto the standard user network in the DR center can break the security model.
In DR design, SecureSys aims to preserve security zones in the alternative location as well.
Update Management on Isolated Networks
Updating systems without internet access requires a dedicated process.
Because updates cannot be downloaded directly over the internet, a controlled update mechanism can be built.
The process;
Obtaining the Update → Security Check → Controlled Transfer → Test → Transfer into the Red Network → Installation
can be carried out in this way.
Backup and Restore on Isolated Networks
The security level of the backups of Red Network systems must also be preserved.
Storing backup data on the standard user network or on uncontrolled storage systems can weaken the isolation approach.
A separate backup repository, an isolated backup network or offline backup options can therefore be evaluated.
Isolated Network Monitoring
Critical networks being isolated does not mean the systems cannot be monitored.
In suitable architectures, SecureSys can enable information such as;
- CPU,
- RAM,
- disk,
- network,
- service status,
- security events
to be forwarded securely to central monitoring systems.
Red Network Health Check
Existing Red Network or isolated network infrastructure can lose its security level over time through newly added access.
Within the SecureSys Isolated Network / Red Network Health Check, components such as the;
- firewall rules,
- VLAN and zone structure,
- routing,
- internet access,
- administrator access,
- Jump Server,
- PAM,
- logging,
- file transfer methods,
- USB policies,
- backup connections
can be assessed.
Isolation Review and Access Analysis
A network being described as "isolated" may not mean it genuinely is.
Additions made over time such as;
- temporary firewall rules,
- servers with dual network cards,
- management connections,
- backup connections,
- third-party access
can break the isolation.
Within an isolation review, SecureSys analyzes the connections between different security zones and helps identify unexpected access paths.
Controlling Third-Party Access
Vendors, maintenance firms or external service providers may need to reach critical systems.
Rather than granting this access directly into the Red Network over VPN, controlled access models such as;
VPN → MFA → PAM → Jump Server → Target System
can be built.
Access can be restricted in terms of duration and privilege, and sessions can be recorded where required.
The Zero Trust Approach on Isolated Networks
A user or device being inside the secure network within the Red Network should not automatically mean it is treated as trusted.
In line with the Zero Trust approach, the;
Never Trust, Always Verify
principle can be applied.
In access decisions, the;
- user identity,
- device,
- location,
- access time,
- target system,
- privilege level
can be evaluated together.
The SecureSys Isolated Network Deployment Process
1. Asset and System Analysis
Critical systems and components processing sensitive data are identified.
2. Data Flow Analysis
Which networks and applications the systems need to communicate with is analyzed.
3. Defining Security Levels
Systems are separated into the Green Network, Red Network and other security zones.
4. Choosing the Isolation Model
Logical segmentation, physical separation or air gap options are evaluated.
5. Network Design
The switch, VLAN, VRF, firewall and routing architecture is built.
6. Secure Transit Layer
Where required, Jump Server, Bastion Host, PAM, MFA and Secure Gateway structures are built.
7. Data Transfer Model
The data flow and file transfer procedures between networks are defined.
8. Logging and Monitoring
SIEM, SOC and monitoring integrations are built.
9. Backup and DR
Isolated backup and disaster recovery requirements are brought into the design.
10. Test and Verification
Unauthorized access paths between networks and the isolation controls are tested.
Why a SecureSys Isolated Network Architecture?
Building Red and Green Network architectures is not simply a VLAN project for the network team to carry out.
Real isolation requires the;
Network + Firewall + System + Identity + PAM + MFA + Endpoint + DLP + SIEM + SOC + Backup
layers to be evaluated together.
SecureSys designs isolated network projects using the infrastructure and cyber security perspectives together.
This approach provides not merely network segmentation but end-to-end security zones, particularly in organizations holding critical information systems.
Frequently Asked Questions About Isolated Network Architectures
What is a Red Network?
A Red Network is the high-security network zone in which critical systems, sensitive data or applications requiring high security are separated from the standard corporate network.
What is a Green Network?
A Green Network can be designed as the controlled corporate network zone where an organization's standard users and general business systems run.
Does a Red Network need a separate switch?
Not always. Depending on risk and security requirements, logical separation can be carried out with VLANs and a firewall, while entirely separate physical switch and network infrastructure can be used in more critical environments.
Does using a VLAN isolate a system completely?
No. A VLAN is a segmentation mechanism. Real isolation also requires routing, firewall policies, management access, data transfers and other connections to be controlled.
What is an air gap?
An air gap is the high-isolation approach in which critical systems are separated physically or architecturally from the internet or other networks.
Can the Red Network reach the internet?
It depends on the architecture. In high-security structures, direct internet access can be blocked entirely. Any necessary access can be restricted through controlled proxy or security gateway systems.
Can remote access be granted to the Red Network?
If the security policy permits it, a controlled access model can be built through layers such as VPN, MFA, PAM and a Jump Server. In environments requiring very high security, remote access can be blocked entirely.
Can an isolated network be monitored by SIEM and the SOC?
Yes. Depending on the architecture, security visibility of isolated environments can be provided using secure or one-way log forwarding.
Protect Your Critical Systems with an Isolated Security Architecture
Separating critical systems from the standard user network should not mean simply creating a different VLAN.
Real isolation requires access paths, administrator accounts, data transfers, backup connections, third-party access and security logs to be controlled together.
With SecureSys you can design Red Networks, Green Networks, Air-Gapped Networks, closed-circuit networks and critical system security zones; have your existing isolated network architecture analyzed; and strengthen its security level.
Contact SecureSys for Isolated Network Deployment, Red and Green Network Architecture or Air Gap Network design.
Do not merely segment your critical systems; isolate the access, the data and the management together.
Want to learn more about this service?
Our expert team will reach out for a free consultation as soon as possible.