Authored pair

Compare.

API gateway / rate-limit edge vs identity-aware policy placement.

All pairs

system · deep · draft

API gateway & edge termination

External clients terminate at an API edge that authenticates, routes, throttles, and translates protocols before reaching internal services — with a teaching reminder that some products split control-plane APIs from byte delivery.

Problem. Exposing every microservice directly to the internet couples auth, quotas, TLS, and routing into every service and makes blast radius hard to reason about.

Scenarios
3
Failures
5
Primary cites
10

Open deep page Presenter

network · deep · draft

Zero-trust / microsegmentation placement

Vendor banner: Cisco Zero Trust Network/Cloud DG + SD-Access / TrustSec. Placement of north–south edge firewalls, east–west inter-VN fusion, and fabric-native SGT microsegmentation — not a Zscaler/ZTNA product catalog.

Problem. Flat trust-inside-perimeter models fail against lateral movement; VLAN-only segmentation does not express identity; hairpinning all east–west through a single firewall pair does not scale.

Scenarios
3
Failures
5
Primary cites
5

Open deep page Presenter