Use case · Segmentation
Segment your network, deny by default
Say what each group of devices is allowed to reach. Everything you did not permit is refused — including traffic from devices in no group at all.
The problem
Flat networks let anything reach anything, so one compromised laptop can reach the finance server. Firewall rules written against addresses break as soon as a laptop moves.
How Weft does it
- Groups and contracts. Put subnets, sites and roaming clients into groups, then write contracts that permit one group to reach another.
- Deny unless permitted. A device outside every group is not exempt; it is refused. Removing a group restricts its members rather than freeing them.
- Policy follows identity. A group tag travels in the VXLAN header between sites, so policy applies to what a device is, not only to its current address.
- Quarantine cuts existing sessions. It is enforced before connection tracking, so isolating a device stops what it is already doing, not only what it tries next.
- You can see it working. The console shows how many packets each contract has allowed or denied, and every site checks that the policy it installed is still the policy in its kernel.