Firewalls, VLANs, DMZs, and the network segmentation basics every later OT-security module builds on.
Before segmenting an industrial network per the Purdue model, you need the underlying IT networking security vocabulary: what a firewall rule actually evaluates, how VLANs isolate broadcast domains without physical rewiring, and why a demilitarized zone (DMZ) exists as a buffer between trust zones rather than a single hard line. This module covers stateful vs. stateless filtering, default-deny posture, and the common misconfigurations — overly permissive ANY→ANY rules, shadowed rules — that undermine an otherwise well-designed segmentation plan.
By the end of this module you should be able to read a basic firewall ruleset and identify whether it actually enforces the segmentation it claims to — the exact skill Module 3 applies to a full industrial network and Module 12 applies to remote-access design.