Segmentation management including visualization, configuration, simulation, or a combination thereof
Technology for segmentation management is described. The segmentation management may include visualization, configuration, simulation, or a combination thereof, of segmentation policies. Segmentation management may include tagging entities communicatively coupled to a network, grouping the entities communicatively coupled to the network into a plurality of groups based at least on one or more tags that are associated with each of the entities, and displaying a user interface for selecting a first group and a second group from the plurality of groups. In response to receiving an input through the user interface, an indication of network traffic is displayed between the first group and the second group, where the network traffic is associated with one or more segmentation rules. In response to receiving additional input through the user interface, segmentation management configures an enforcement point with the segmentation rules.
1 . A method comprising:
tagging a plurality of entities communicatively coupled to a network;
grouping the plurality of entities communicatively coupled to the network into a plurality of groups based at least on one or more tags that are associated with each of the plurality of entities;
monitoring and storing network traffic;
displaying one or more controls for selecting a first group and a second group from the plurality of groups;
in response to receiving an input associated with the one or more controls, displaying, by a processing device, an indication of network traffic between the first group and the second group, the network traffic being associated with one or more segmentation rules received through the input or obtained from storage, wherein displaying the indication of the network traffic comprises performing a simulation with the stored network traffic in view of the one or more segmentation rules, and displaying network traffic resulting from the simulation; and
in response to receiving a second input through the one or more controls, configuring an enforcement point with the one or more segmentation rules, the enforcement point being associated with the first group and the second group.
2 . The method of claim 1 , wherein the one or more controls comprises a first control configured to apply the one or more segmentation rules to an entire group, and a second control to apply the one or more segmentation rules to a single entity of the plurality of entities.
3 . The method of claim 1 , further comprising, in response to receiving, through the one or more controls, a selection of a service that is configured on an entity of the first group or the second group, displaying a subset of the network traffic resulting from the simulation, wherein the subset of the network traffic is associated with the service.
4 . The method of claim 1 , wherein tagging the plurality of entities includes generating one or more tags for each of the plurality of entities wherein at least one of the one or more tags are determined based on a characteristic of an entity that is independent of internet protocol (IP) address.
5 . The method of claim 4 , wherein grouping the plurality of entities is performed based on commonality of the one or more tags among the plurality of entities.
6 . The method of claim 1 , wherein displaying the indication of the network traffic comprises displaying an indication comprising at least one of a first visual indication associated in response to allowed communication between a first entity of the first group and a second entity of the second group, a second visual indication in response to partial allowed communication between the first entity of the first group and the second entity of the second group, and a third visual indication in response to blocked communication between the first entity of the first group and the second entity of the second group.
7 . The method of claim 1 , further comprising, in response to receiving a third input associated with the one or more controls, displaying a subset of the network traffic resulting from the simulation, wherein the subset of the network traffic is authorized, and in response to receiving a fourth input associated with the one or more controls, displaying a second subset of the network traffic resulting from the simulation, wherein the second subset of the network traffic is unauthorized.
8 . A system comprising:
a memory; and
a processing device, operatively coupled to the memory, to:
tag a plurality of entities communicatively coupled to a network;
group the plurality of entities communicatively coupled to the network into a plurality of groups based at least on one or more tags that are associated with each of the plurality of entities;
monitor and store traffic of the network;
display one or more controls for selecting a first group and a second group from the plurality of groups;
in response to receiving an input associated with the one or more controls, display an indication of network traffic between the first group and the second group, the network traffic being associated with one or more segmentation rules received through the input or obtained from storage, wherein to display the indication of the network traffic comprises to perform a simulation with the stored network traffic in view of the one or more segmentation rules, and to display network traffic resulting from the simulation; and
in response to receiving a second input through the one or more controls, configure an enforcement point with the one or more segmentation rules, the enforcement point being associated with the first group and the second group.
9 . The system of claim 8 , wherein the one or more controls comprise a first control configured to apply the one or more segmentation rules to an entire group, and a second control to apply the one or more segmentation rules to a single entity of the plurality of entities.
10 . The system of claim 8 , wherein the processing device is further to, in response to receiving, through the one or more controls, a selection of a service that is configured on an entity of the first group or the second group, display a subset of the network traffic resulting from the simulation, wherein the subset of the network traffic is associated with the service.
11 . The system of claim 8 , wherein to tag the plurality of entities comprises to: generate one or more tags for each of the plurality of entities wherein at least one of the one or more tags are determined based on a characteristic of an entity that is independent of internet protocol (IP) address.
12 . The system of claim 11 , wherein to group the plurality of entities is performed based on commonality of the one or more tags among the plurality of entities.
13 . A non-transitory computer readable medium having instructions encoded thereon that, when executed by a processing device, cause the processing device to:
tag a plurality of entities communicatively coupled to a network;
group the plurality of entities communicatively coupled to the network into a plurality of groups based at least on one or more tags that are associated with each of the plurality of entities;
monitor and store traffic of the network;
display one or more controls for selecting a first group and a second group from the plurality of groups;
in response to receiving an input associated with the one or more controls, display, by the processing device, an indication of network traffic between the first group and the second group, the network traffic being associated with one or more segmentation rules received through the input or obtained from storage, wherein to display the indication of the network traffic comprises to perform a simulation with the stored network traffic in view of the one or more segmentation rules, and to display network traffic resulting from the simulation; and
in response to receiving a second input through the one or more controls, configure an enforcement point with the one or more segmentation rules, the enforcement point being associated with the first group and the second group.
14 . The non-transitory computer readable medium of claim 13 , wherein the one or more controls comprise a first control configured to apply the one or more segmentation rules to an entire group, and a second control to apply the one or more segmentation rules to a single entity of the plurality of entities.
15 . The non-transitory computer readable medium of claim 13 , wherein the processing device is further to, in response to receiving, through the one or more controls, a selection of a service that is configured on an entity of the first group or the second group, display a subset of the network traffic resulting from the simulation, wherein the subset of the network traffic is associated with the service.
16 . The non-transitory computer readable medium of claim 13 , wherein to tag the plurality of entities comprises to: generate one or more tags for each of the plurality of entities wherein at least one of the one or more tags are determined based on a characteristic of an entity that is independent of internet protocol (IP) address.
17 . The non-transitory computer readable medium of claim 16 , wherein to group the plurality of entities is performed based on commonality of the one or more tags among the plurality of entities.