Securing Your Network
Defence in Depth
No single tool stops every attack. Good network security uses layers, so that when one control fails the next one still protects you. This is called defence in depth. In this lesson you will meet four building blocks: firewalls, VPNs, segmentation and modern Wi-Fi encryption.
Firewalls
A firewall is a gatekeeper that allows or blocks traffic using rules. Each rule looks at things such as source IP, destination IP, port and protocol.
ALLOW tcp any -> 10.0.0.5 port 443 # public website
ALLOW tcp 10.0.1.0/24 -> 10.0.0.5 port 22 # admins only
DENY any any -> any any # default deny
Two principles matter most:
- Default deny: block everything, then allow only what is needed.
- Least privilege: allow the narrowest source and port possible.
Types include packet-filtering firewalls (fast, simple), stateful firewalls (track connections) and next-generation firewalls (inspect applications and threats). Home routers have a basic firewall built in, and companies add dedicated appliances or cloud firewalls. You will study these in depth in Module 5.
VPNs
A Virtual Private Network creates an encrypted tunnel between your device and a VPN server. Anyone watching the local network sees only scrambled data going to one place.
Good uses
- Protecting traffic on public Wi-Fi in a cafe, hotel or airport.
- Letting staff reach the office network securely from home. Many banks, including Access Bank, and global firms use a corporate VPN or zero-trust access for remote work.
Limits: a VPN does not make you anonymous or protect you from malware or phishing. It just moves your trust from the local network to the VPN provider, so choose carefully.
Network Segmentation
Segmentation splits one big network into smaller zones, so that a breach in one place cannot spread everywhere.
[ Guest Wi-Fi ] [ Staff laptops ] [ Servers ] [ Payment systems ]
\ | | /
[ Firewall with rules between zones ]
Examples:
- Guest Wi-Fi is separated from staff devices.
- IoT devices (cameras, smart TVs) sit in their own VLAN.
- Payment or database servers are reachable only from the application servers that need them. This is a requirement of standards such as PCI DSS, used by banks and fintechs in Nigeria and worldwide.
Segmentation turns a total compromise into a contained incident. It is one of the most effective defences against ransomware spreading.
Wi-Fi Security: WPA3
Wi-Fi encryption has improved over time:
| Standard | Status |
|---|---|
| WEP | Broken. Crackable in minutes. Never use |
| WPA | Obsolete |
| WPA2 (AES) | Still common. Vulnerable to offline password guessing if the password is weak |
| WPA3 | Current best. Protects against offline guessing and gives each user unique keys |
Practical tips for a home or small business in Lagos or anywhere:
- Use WPA3, or WPA2 with AES if WPA3 is unavailable.
- Choose a long passphrase (four or more random words).
- Change the router's default admin password and update its firmware.
- Turn off WPS and remote administration.
- Put guests on a separate guest network.
A Simple Hardening Checklist
- Default-deny firewall rules, reviewed regularly.
- Only necessary ports open (check with a scan).
- Encrypted protocols only (HTTPS, SSH, SFTP).
- Segmented zones for guests, staff, servers and payments.
- VPN or zero-trust access for remote staff.
- WPA3 Wi-Fi with a strong passphrase.
- Logging and monitoring so that you notice problems.
Next you move to the Linux command line, the everyday tool of security professionals.
Try it yourself
Key Takeaways
- Defence in depth uses multiple layers, so one failure does not mean a total compromise.
- Firewalls should default deny and allow only the narrowest source, port and protocol that is needed.
- A VPN encrypts traffic across untrusted networks. It is not anonymity, and it does not stop phishing or malware.
- Segmentation contains breaches by separating guest, staff, server and payment zones. It is required by standards such as PCI DSS.
- Use WPA3 (or WPA2-AES), a long passphrase, updated firmware and a changed admin password. Never use WEP.
Quick Quiz
1.What does a 'default deny' firewall policy mean?
2.Why is network segmentation effective against ransomware?
3.Which Wi-Fi security standard should you choose today?
Ready to go further?
CareerEx gives you structured 12-week training, live classes every Saturday and Sunday, real tutor feedback, and a certificate. Join the next cohort.
Join CareerEx