Transcription of SD-Access Segmentation Design Guide - Cisco
{{id}} {{{paragraph}}}
S Cisco VALIDATED DESIGNSD-Access Segmentation Design GuideMay 2018 Table of ContentsCisco Validated DesignTable of ContentsIntroduction ..1 Intent-based networking and Segmentation ..2 Understanding virtual networks and SGTs in SD-Access ..4 Enforcement of traffic destined external to the fabric ..9 Defining network segments ..16 Virtual networks or scalable group tags ..17 Use ..21 Manufacturing ..22 Healthcare ..24 PCI and retail ..26 Electric power ..26 Appendix A: network Segmentation overview: A brief history ..28 VLANs and private VLANs ..28 Virtual routing and forwarding instances ..29 Cisco TrustSec Software-defined B: References ..34page 1 Cisco Validated DesignIntroduction Introduction An ever-growing number of cyberattacks are launched daily against organizations of all types, carried out by individuals, organized syndicates, and state-sponsored hackers. Whether for purposes of financial gain through acquiring credit card data, extortion through ransomware, access to personal data for identity theft, or disruption of services, these attacks are continually growing in frequency and sophistication.
devices. A given network segment, and the policies it represents, may be extended anywhere within an organization where one of the business-relevant applications or functions reside. Historically, when implementing VRFs or Cisco TrustSec, manual configuration of the network infrastructure is unavoidable. Whether extending VRFs through VRF-
Domain:
Source:
Link to this page:
Please notify us if you found a problem with this document:
{{id}} {{{paragraph}}}