This document discusses ControlCircle's design of a segmented network for CloudStack management domains. Key points: - ControlCircle designed separate networks for DMZ, control, management, guest, public and database traffic to improve security and scale. - Troubleshooting use cases like ISO uploads was challenging due to limited documentation on segmented designs. - Lessons learned include relying on logs, considering network agility, understanding use cases in advance, and documenting designs and rules. The CloudStack community provides valuable troubleshooting support.