Network Penetration Testing

Also known as:Netzwerk Pentest · Network Pentest · Infrastructure Pentest

Network Penetration Testing is the authorized security assessment of an organization’s network infrastructure — both internal and external. It targets firewallsFirewallControls network traffic based on defined rules and security policies., routers, switches, VLANs, VPNVirtual Private NetworkProvides an encrypted tunnel over an untrusted network. gateways, DNS servers, and the services running on network-connected hosts to identify exploitable weaknesses that could allow unauthorized access, lateral movement, or data exfiltration.

A network pentest examines whether segmentation boundariesNetwork SegmentationSeparates network segments to control access and limit lateral movement. hold under adversarial pressure, whether network services expose unnecessary attack surface, and whether an attacker who gains a foothold on one segment can pivot to reach sensitive assets elsewhere.

Who commissions this test?

Network penetration tests are commissioned by CISOs, IT operations managers, network security teams, and compliance departments. They are a staple of enterprise security programs and frequently required by regulatory frameworks. PCI DSS mandates quarterly external vulnerability scans and annual penetration tests for organizations processing cardholder data. ISO 27001 and SOC 2 audits expect evidence of periodic infrastructure testing.

Test objectives

The objectives of a network pentest are to identify all reachable network services and their vulnerabilities, to evaluate the effectiveness of network segmentation and access controls, to determine whether an external attacker can breach the perimeter or an internal attacker can move laterally, and to validate that network security devices (firewalls, IDS/IPS, NAC) enforce their intended policies. External tests focus on the perimeter — what an internet-based attacker sees. Internal tests simulate an adversary who has gained physical or VPN access to the corporate network.

What is tested?

External scope includes public-facing IP ranges, perimeter firewalls, DMZDemilitarized ZoneA separate network segment for publicly accessible services located between internal and external networks. services (web servers, mail servers, DNS, VPN concentrators), exposed management interfaces, and external DNS records. Internal scope covers LAN and WLAN segments, inter-VLAN routing and segmentation enforcement, internal DNS and DHCP services, file shares (SMB/NFS), Active Directory integration, network device management planes (SSH, SNMP, web consoles), printers and IoT devices on the network, and network monitoringDeep Packet InspectionAnalysis of packet content and protocol characteristics beyond mere header information. evasion. The boundary between network and application testing is often fluid — a network pentest will exploit a vulnerable service discovered on an open port, while a dedicated application test goes deeper into application logic.

Common findings

  • Open ports running unnecessary or outdated services (Telnet, FTP, unpatched SSH)
  • Default or weak SNMP community strings (public/private) providing read or read-write access to network device configurations
  • Weak or overly permissive firewall rules allowing unintended traffic between zones
  • VLAN hopping via double-tagging or DTP negotiation on misconfigured switch ports
  • Missing network segmentation — flat networks where a compromised workstation can reach database servers, management interfaces, and sensitive subnets
  • Unencrypted protocols in use (HTTP for management consoles, Telnet for switch administration, FTP for file transfers)
  • Outdated firmware on routers, switches, and firewalls with known CVEs
  • Exposed management interfaces (web consoles, SSH, SNMP) accessible from user VLANs or the internet
  • DNS zone transfers enabled to arbitrary requestors, leaking the full internal DNS map
  • ARP spoofing and MITM opportunities due to missing dynamic ARP inspection (DAI)
  • Rogue DHCP servers or DHCP starvation attacks possible due to missing DHCP snooping
  • Weak VPN configurations (IKEv1 aggressive mode, weak cipher suites, split tunneling exposing corporate traffic)
  • Missing 802.1X on wired ports, allowing unauthorized devices to connect

Typical engagement workflow

Initial inquiry — The organization reaches out for a network security assessment. The pentest team gathers basic information: number of external IPs, size of internal network, number of sites, and whether the focus is external, internal, or both.

Scoping conversation — A detailed discussion with network engineers, IT security, and stakeholders to understand the network architecture, existing segmentation model, security devices in place, and any areas of particular concern. The tester learns about network topology, critical assets, and the boundary between network and application scope.

Proposal and approval — The formal proposal specifies external and internal scope, testing methodology (automated scanning, manual exploitation, social engineering elements if applicable), duration, and deliverables. It is reviewed by IT management, network operations, and legal.

Scope definition — External IP ranges, internal subnets, VLANs, physical locations for on-site internal testing, and wireless networks are documented. Excluded systems (e.g., fragile legacy systems, production databases) are explicitly listed. Testing windows — especially for disruptive tests like DoS validation — are agreed.

Letter of engagement — Signed authorization covering legal protection, IP ranges in scope, permitted testing techniques, escalation contacts, and communication procedures. For external tests, this document may need to be shared with hosting providers or ISPs.

Additional authorizations — Cloud-hosted infrastructure (AWS VPCs, Azure VNets) may require provider notification. Co-location facilities may need advance notice.

Information exchange — The client provides network diagrams, IP range lists, VLAN documentation, and firewall rule summaries depending on the agreed approach. For internal tests, a physical drop point or VPN access is arranged. For Black-Box external tests, only the company name or domain list is provided.

Kick-off call — Final alignment with network operations, IT security, and the pentest team. Emergency contacts, monitoring expectations (will SOC/NOC see the test traffic?), and the handling of service disruptions are confirmed.

Execution — External testing begins with passive reconnaissance (OSINT, DNS enumeration, certificate transparency logs) followed by active port scanning, service fingerprinting, vulnerability identification, and exploitation. Internal testing starts with network discovery, VLAN enumeration, service scanning, credential attacks (SNMP, default credentials, LLMNR/NBT-NS poisoning), and pivoting through compromised systems to test segmentation boundaries. Stakeholders receive progress updates, and any critical findings (internet-exposed RCE, trivially exploitable vulnerabilities) are reported immediately.

Vulnerability assessment and rating — Findings are documented with evidence (screenshots, packet captures, tool output), rated by severity (CVSS), and contextualized with business impact.

Final report — The report presents each finding with technical detail, evidence of exploitation, affected systems, and prioritized remediation guidance. An executive summary translates technical findings into business risk.

Presentation — Results are presented to IT leadership, network engineering, and security management. The presentation highlights the most critical findings and demonstrates the most impactful attack chains.

Project closure — Remediation timelines, retest scheduling, and recommendations for ongoing network security monitoring and hardening are agreed.

Who should commission this test — and when?

All organizations with network infrastructure should conduct regular network penetration tests. This applies to enterprises, SMBs, data center operators, managed service providers, and any organization subject to compliance frameworks that mandate infrastructure testing. Network pentests should be performed after significant network redesigns or architecture changes, when deploying new office locations or data centers, after firewall rule overhauls, when introducing new VPN or remote access solutions, and on a regular annual cycle. PCI DSS requires annual penetration tests and quarterly external scans. Organizations that have experienced a network-based breach should assess their infrastructure as part of post-incident remediation.

  • Penetration TestingPenetration TestingAuthorized, methodical testing of a system for exploitable weaknesses, to find them before real attackers do.: Authorized, methodical testing of systems for exploitable weaknesses.
  • Network SegmentationNetwork SegmentationSeparates network segments to control access and limit lateral movement.: Dividing a network into isolated zones to limit lateral movement and contain breaches.
  • FirewallFirewallControls network traffic based on defined rules and security policies.: A network security device that filters traffic based on defined rules.
  • DMZDemilitarized ZoneA separate network segment for publicly accessible services located between internal and external networks.: A network zone that separates public-facing services from the internal network.
  • VPNVirtual Private NetworkProvides an encrypted tunnel over an untrusted network.: An encrypted tunnel providing secure remote access to internal networks.
  • Deep Packet InspectionDeep Packet InspectionAnalysis of packet content and protocol characteristics beyond mere header information.: Network analysis that examines the full content of packets beyond header information.