Network segmentation is one of the most effective things you can do for OT and IT security. It is also one of the easiest to plan badly. Zones, VLANs, communication relationships, firewall rules, an operating model, responsibilities, a realistic roadmap. Most teams try to hold all of that in a spreadsheet and a Visio diagram that were never designed for the job.
Why a tool, not a spreadsheet
A segmentation concept is not one artefact. It is a zone model, a VLAN and subnet plan, a communication matrix, a derived firewall rule set, an operating model with roles and responsibilities, and an implementation roadmap, and all of those have to stay consistent with each other. The moment a zone changes, the matrix, the rules and the roadmap should change with it. Spreadsheets and drawing tools do not do that.
The narrowin segmentation toolbox is a browser-based planning environment built specifically for this. It is the same toolbox the firewall rule cleanup config parser belongs to, here seen as a whole. Three principles run through it:
Structured, not ad hoc
Pre-built templates for the Purdue model, enterprise campus and IT/OT convergence: a starting structure instead of a blank page.
Vendor-independent
The toolbox plans the design, not a specific vendor's box. No lock-in: the output is an architecture, not a configuration.
Ready in the browser
No installation, no account for the open tools, and the working data stays local in the browser; nothing is sent to a server.
Three areas, one goal
The toolbox covers the whole planning process: from the technical network design, through the organisational operating model, to the implementation roadmap. It is organised into three areas, each with its own set of tools.
Area 01
Network segmentation
The technical design: zones, VLANs, subnets, the communication relationships between them and the resulting firewall rule set.
Area 02
Operating model
The organisation around the segmented infrastructure: roles, processes, responsibilities and a RACI that says who decides what.
Area 03
Roadmap planning
From analysis to implementation: a timeline, a prioritisation by risk and effort, and structured work packages.
Define what may talk to what
Once the zones exist, the central question is which of them may communicate, and over which protocols. The communication matrix makes that decision explicit: every pair of zones gets a deliberate verdict, and the result is the authoritative reference the firewall rule set is derived from.
The matrix below is a working example with eight Purdue zones, using the toolbox's own demo data. Select any cell to see the protocols permitted across that zone boundary.
More than a network diagram
Segmentation projects rarely fail on technology. They fail on organisation: nobody defined who owns a zone, who approves a new communication path, or what happens when a device joins the network. A clean zone model with no operating model behind it is outdated within months.
That is why the toolbox treats the operating model as a first-class area, not an afterthought. It maps roles and teams, processes, a RACI matrix and FTE capacity onto the segmented infrastructure, so the design has an owner before it has a single rule.
A roadmap you can actually run
A complete segmentation concept is rarely fewer than thirty work packages spread over several quarters: from network documentation, through zone design and firewall cleanup, to NAC, monitoring and compliance. Planned as one block, it stalls.
The roadmap planner ships with a template, "Network Security & Resilience", of 34 work packages across eight categories. Each package carries an owner, an effort-versus-benefit rating, its dependencies and a target quarter. Priorities follow risk and effort (quick wins first), and progress is tracked per category, not just per quarter.
Starting in a brownfield network
Most segmentation projects do not start on a greenfield. They start in networks with organically grown VLANs, undocumented communication paths and inherited firewall rules. The toolbox is built for exactly that, not as a greenfield designer but as a planning tool that takes the existing environment seriously, in three moves.
1
Capture
Capture the baseline
Config import reads the existing firewall rules, interfaces and zones. The VLAN Planner documents the current structure. Network Explorer data adds topology and port context.
2
Plan
Plan the target
Security Zones map the segments to Purdue levels. The communication matrix defines the allowed transitions. IPAM and the operating model give the target architecture its structure.
3
Implement
Implement in waves
The roadmap planner turns the target into waves with maintenance windows, responsibilities and dependencies. No big bang, controlled packages instead.
What makes it practical
The toolbox is deliberately lightweight where it can be, so that planning work is never blocked on installation, licences or a server.
Browser-based
Runs entirely in the browser. No installation, no server, and no account for the open tools.
Local data storage
Working data stays in the browser. Nothing is sent to a server while you plan.
Templates & presets
Purdue model, enterprise campus, hospital IT/OT and other industry-specific starting points.
Export & documentation
Export zones, VLANs and the matrix as JSON, PDF or a structured report.
Config import
Import firewall configurations and analyse the rule set automatically, with the parser from the cleanup work.
German & English
Fully bilingual. Switch language at any time; the data is preserved.