---
title: "Segment a port and airport network, no changes | Edge SDN"
description: "A port and airport service provider segmented a wide multi-vendor network inside its existing VLANs, with no change to IP addresses, hardware or third-party systems."
url: https://www.edge-sdn.com/success-cases/ports-and-airports/
last_updated: 2026-10-04
---

Critical infrastructure · Edge SDN

# Secure a port and airport network you do not fully control

Service provider for a port and an airport

Vendors work as before, lateral traffic blocked

In short

A service provider for a port and an airport ran a wide network of fibre and wireless links. Cameras, gates, fire systems and sensors came from many vendors, often as black boxes it could not touch. The Edge SDN platform built layered zones inside the existing VLANs, on the existing switches. Nothing changed for the vendors and lateral traffic dropped.

## The challenge

- Many sites linked by fibre and wireless bridges, built for convenience
- Safety systems from outside vendors: black boxes with no access
- Vendors forbid VLAN changes and added firewalls
- Protection only from basic VLANs and border firewalls

## How we did it

1. **Start with the most sensitive VLANs**Work where the risk is highest first.
2. **Analyse the traffic**Keep operational traffic. Stop devices from seeing each other.
3. **Build zones in layers**Layered zones inside each VLAN make it easy to add or change devices.
4. **Enforce at the access switches**Stop east-west movement with no new hardware.

## The results

- **Fewer IDS alerts**Much less traffic between zones.
- **Vendors work as before**Same network, same access to their systems.
- **Block a zone at the switch**A new control for problems and incidents.
- **No unknown devices**Unauthorised additions are no longer possible.

### Read the full story

## The situation

The provider serves a port and an airport. Its network covers many zones, linked by optical fibre and wireless bridges, and was built for convenience rather than security.

The network carries safety and operational systems: surveillance cameras, environmental sensors, actuators, access gates, bulkhead controls, energy monitoring, fire suppression and emergency networks. Different third-party vendors supply and maintain many of them.

## What made it hard

The IT manager had little control over large parts of the network. Many devices were black boxes with no access for security tools. Vendors worked on their own systems without supervision.

Protection came only from basic VLANs and border firewalls. Vendors of systems such as access gates and fire safety did not allow VLAN changes or extra firewalls. Any disruption could affect safety at two busy transport hubs.

The team needed more security **without changing IP addresses, the network design or the vendors’ systems**.

## What we did

We used the Edge SDN platform, starting with the most sensitive VLANs. Inside them we analysed the traffic and built perimeters around devices. Operational traffic still passes, but devices can no longer see each other directly, which blocks lateral movement during an attack.

Each VLAN got **security zones in several layers**. New or changed devices fit in without complex reconfiguration.

Enforcement runs on the **existing access switches**, managed from the Edge SDN platform. Upper-level switches separate logical zones inside the existing VLANs. In parts of the network with predictable traffic and non-SDN switches, the gains came without extra probes.

## What changed

Traffic between zones dropped sharply and the border IDS raises fewer alerts. The network works as before, so vendors reach their systems exactly as they did.

The IT team can now **block traffic in a single zone, at the access switch**, when something goes wrong. That was impossible before.

A fault or misconfiguration in one zone no longer spreads to others, which makes vendors’ work easier and safer. Unauthorised devices can no longer be added. Vendors also became more disciplined in how they work.

**Ports and airports are NIS2 sectors**

NIS2 lists airport and port managing bodies, and the entities that operate installations, works and equipment inside airports and ports. [\[Directive (EU) 2022/2555, Annex I point 2\]](https://eur-lex.europa.eu/eli/dir/2022/2555/oj/eng)

Product used

### Edge SDN

[Explore Edge SDN](https://www.edge-sdn.com/products/edge-sdn/)

The customer is not named on this page. Results describe this project and depend on each network.

## See a critical CVE hit a machine

We show you the moment that matters: a new vulnerability lands. One machine is exposed and the other is not. The customer notice is ready to send.

Meet us at 35.BI-MU, fieramilano Rho, 13–16 October 2026
