Network Security Diagram Software

Draw firewall zones, trust levels and the flows between them, and keep each zone's rules, owner and review notes one click behind it.

Free forever on the Personal plan

Network security diagrams: an example

Network security diagram of a firewall pair with one interface per zone: internet, guest Wi-Fi and remote staff on the untrusted side, and staff, servers, cloud and management on the internal side, each zone coloured by trust level.
  • Zones coloured by trust

    Untrusted to privileged at a glance, so a risky path stands out before anyone reads a rule.

  • Allowed flows on record

    Each zone opens a table of what it may reach, on which ports, and why.

  • An owner for every rule

    Owners, approvals and review dates sit behind the zone they apply to.

The basics

What is a network security diagram?

A network security diagram shows how a network is divided into security zones and how traffic between them is controlled: the firewalls, the segments behind each interface, remote access, management paths and the connections to cloud and the internet. Zones are usually coloured by trust level, from untrusted to privileged.

Security and network teams use these diagrams for firewall reviews, audits, incident response and change approval. Auditors often ask for one; PCI DSS, for example, requires an accurate diagram of the connections into the cardholder data environment. The drawing shows the boundaries, and the rules that enforce them belong right behind it.

In Blueprintr each zone can open a stratum with its allowed flows, owner and review date, so the security diagram and the policy it describes are one document.

Why Blueprintr

Security diagrams that stand up to a review

Draw the boundaries once, then keep the rules and the reasoning behind them.

  • Zones, firewalls and VPNs

    Draw each zone as a container coloured by trust, with firewalls, routers and VPN gateways from the network icon pack, or your own SVG icons.

    Vellum
  • Rules behind each zone

    Give every zone a stratum with its allowed flows, ports, approvals and review date, in tables a reviewer can scan.

    Stratum
  • Cloud security views

    On the Team plan, Continuum Cloud reads AWS and Azure read-only and adds Security groups and Public exposure views, so you can check what is open to the internet.

    Continuum
  • See what changed

    Every publish keeps a snapshot. On the Team plan you can compare the text of two versions, strata included, to see which rules changed before a review.

  • Sign-off before it goes live

    On team-owned blueprints, require an admin or named approvers to sign off a change before it is merged into the published diagram.

  • Shared with the right people

    Keep the diagram private and share it with named reviewers, or send an unlisted link. On Premium you can add a password.

    Blueprints

How to

How to make a network security diagram in Blueprintr

  1. Create a blueprint

    Sign up free, create a private blueprint and open the Vellum editor.

  2. Draw the zones

    Add a container for each zone and colour it by trust level, from untrusted to privileged.

  3. Add the firewalls

    Place each firewall with an interface per zone, and connect every zone to the interface that serves it.

  4. Record the rules

    Right-click a zone and add a stratum with what it may reach, the ports, the owner and the last review date.

  5. Share it for review

    Share the blueprint with your reviewers, then publish each approved change.

Start from a template

Zero-trust access architecture

Users and devices checked by a policy engine for identity, MFA and device posture before a ZTNA proxy brokers each session, with strata for policies and posture checks.

Open the Compendium

FAQ

Questions about network security diagrams

Is this network security diagram software free?

Yes. The Vellum editor, the network icon pack and strata are on the free Personal plan. Cloud security views with Continuum Cloud, version comparison and approvals are part of the Team plan.

What should a network security diagram include?

Every zone and its trust level, the firewalls between them, remote access, management paths, connections to the internet and cloud, and the allowed flows. Record the owner and last review date beside each zone.

Can Blueprintr read my firewall rules?

Not from on-premise firewalls; you record the rules in strata. On the Team plan, Continuum Cloud reads AWS and Azure read-only, including security groups, and shows them in a Security groups view.

Can I share a network security diagram with an auditor?

Yes. Share a private blueprint with named people, or send an unlisted link, with a password on Premium. Every publish keeps a snapshot, and on the Team plan you can show earlier versions.

How do I show trust levels on a network diagram?

Colour each zone's container by trust, from red for untrusted to violet for privileged, and add the meaning of each colour in a stratum. The example above uses that scheme.

Can I keep the security diagram separate from the main network diagram?

Yes. Keep it as its own blueprint with tighter sharing, or as a second diagram tab beside the network diagram. Each tab has its own shapes and strata.

Draw the boundaries once, and keep the rules behind every zone