Segmentation Atlas

What your network is doing

We read every one of the 9,793 connections in this file and worked out the smallest set of rules that keeps the network working. The 21 things that would stop are listed, with what breaks and who to ask.

25 rules to write one for each thing that has to keep working
21 things stop working each one listed with what breaks and who owns it
8 groups to work through one at a time, starting with Quahog Recon

Rule 1 is not written yet. Nothing below is safe to switch on until you say who administers these machines and how they get in — otherwise the first wall you put up locks you out. Define administrative access

From 9,793 connections watched across 22 machines. 7 of the rules need a decision from you before they can go on, and 110 risky ports are reachable today that no rule asks for.

Reading data.csv 9,793 connections · last seen 11 Sep 2026 · 5.3 MB · read in 1.27 s use a different file

Nothing can be saved here: the web server is not allowed to write to /var/www/coloryzer.blaineland.net/public_html/exports or cache/. Hand both folders to the web server and try again.

9,793 separate connections, read from 10,000 lines across 1 file. 207 were the same connection seen again, so they were folded together rather than counted twice.

Only show
Put the wall around one wall per application · 8 walls · 25 rules

First: who administers these machines?

Before a single wall goes up, one rule has to exist — the one that keeps you able to reach a machine after everything else is shut. Nothing else on this page is safe to switch on until it does, because everything not allowed is stopped, and that includes the way you get in to fix it.

This is not worked out from the traffic. Which addresses count as administrative, and which services you use to get in, are your decisions — so they are asked for, not guessed. The lists below are filled from this export.

Where does administration come from?

Pick either, or both.

Named networks in this export

A named network is one or more subnets in CIDR or address ranges. If your admin range is not here yet, add it in the console and export again.

Or machines carrying a label — machines you log in through are usually named this way

Hold or Ctrl to pick more than one. The number is how many machines carry that value.

How do you get in?

The ports and protocols you actually administer over — whatever your access method is.

Write them as port/protocol, separated by commas. A port on its own is taken as TCP. ICMP on its own is allowed for reachability checks.

Anything worth writing down?

Where the traffic goes

the whole network on one picture

Each card is a group of machines. Each line is traffic between two of them, coloured by how much it matters. Click a group to see only its traffic, or a line to see what is on it.

More about this picture

Every card is one label value, and the dashed outline around a row is the environment those groups sit inside — that nesting is the order the rules are written in. Use Group by at the top to widen or narrow it: environment is the coarsest view, role the finest. A dashed line means traffic was attempted but nothing ever completed a connection. Where there is too much to draw at once, the map shows the most serious and says so underneath.

critical high watch nothing ever connected
Click a group to focus on it · Esc to close

Where to start

which group to take first

Ordered by how much exposure each one removes against how many rules you have to get right first. Take them one at a time — write it, try it, turn it on, watch it. Click one to see it on the map.