DSE security knowledge hub

Networks & Infrastructure
Knowledge

Guidance for resilient networks, Wi-Fi, firewalls, cabling, power, exposure reduction, and connected-device planning.

DSE-authoredOfficial sourcesReviewed guidance
Explore this topic

Networks & Infrastructure knowledge center

Guidance for resilient networks, Wi-Fi, firewalls, cabling, power, exposure reduction, and connected-device planning.

Start with the cornerstone guide
DSE post stream

Networks & Infrastructure

50 articles
DSE visual briefNetworks & infrastructure
ChecklistImportantITNetworks & Infrastructure

Govern Windows DNS scavenging as a deletion change, not routine cleanup

Windows DNS aging can identify stale dynamic records, and scavenging can delete them. Inventory timestamps and registration owners, align intervals with DHCP and client behavior, restrict scavenging servers, pilot one zone, and prove recovery before enabling automation.

Published Reviewed 3 min readBy Gavin Stewart
Read the checklist
DSE visual briefIdentity & cloud

Deploy SMB over QUIC only after identity, port, and fallback testing

SMB over QUIC protects Windows file access with TLS 1.3 over UDP 443, but Windows clients can still prefer TCP and external authentication can fall back to NTLM. Prove transport, identity, certificates, and renewal before production.

Published Reviewed 4 min readBy DSE Security Editorial Team
Read the checklist
DSE visual briefNetworks & infrastructure

Use RPKI route-origin validation without confusing Valid with safe

RPKI lets resource holders authorize which ASN may originate a prefix and lets operators validate BGP origins. It does not validate the full AS path or prove a route is benign. Build careful ROAs, redundant validators, policy, and monitoring.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the playbook
DSE visual briefNetworks & infrastructure

Design Azure Private Endpoint DNS before the first private link

An approved Azure Private Endpoint can still fail when clients resolve the public address or a private zone returns NXDOMAIN. Design service-specific zones, VNet links, hybrid forwarding, fallback, ownership, and tests before deployment.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the guide
DSE visual briefNetworks & infrastructure

Test Path MTU across tunnels and cloud edges before applications stall

VPN, overlay, encapsulation, and cloud paths can carry less payload than an endpoint interface suggests. Validate bidirectional Path MTU, ICMP behavior, transport adaptation, and representative applications before intermittent stalls reach production.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the playbook
DSE visual briefNetworks & infrastructure

Govern IPv6 even when the network is called IPv4-only

IPv6 may be active on endpoints, servers, and network equipment before an organization intentionally deploys it. Unmanaged IPv6 creates a parallel path around inventories, filtering, monitoring, segmentation, and incident procedures designed only for IPv4.

Published Reviewed 4 min readBy Gavin Stewart
Read the checklist
DSE visual briefPhysical security

Measure live-video delay before operators must act

A stream can be clear and still arrive too late. Measure sensor-to-screen delay through the production camera, network, VMS, decoder, workstation, and display—under normal and stressed conditions—before live video supports a time-sensitive response.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the checklist
DSE visual briefPhysical security

Commission radar as a perimeter sensor, not a magic field

Radar can add reliable movement, position, and speed data where light, fog, shadows, or privacy limit video. Its blind spots, reflections, classification limits, zones, and response integrations still need real-scene acceptance testing.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the checklist