Segment around trust and function
VLAN count is not a security strategy by itself. Identify groups of systems with different trust, exposure and communication requirements, then enforce traffic boundaries at appropriate control points.
Document allowed flows
Segmentation projects fail when application dependencies are unknown. Build an inventory of required flows, DNS, authentication, management and monitoring paths before enforcement. Log denied traffic during controlled rollout to identify omissions.
Keep management possible
Operations teams still need secure administrative access, monitoring and backup across segments. Design these paths explicitly rather than punching broad exceptions through the controls after deployment.
AL Group can assess, design, implement and operate the underlying technology rather than stopping at advice.
Talk to an engineer