Presenter mode
Zero-trust / microsegmentation placement
Step 1 / 3
Access auth binds user/device posture via ISE before fabric forwarding. Identity is part of the published zero-trust composition.
Step 1 / 3
ISE assigns dynamic source SGTs (e.g. eng vs iot). Keep the role set on the order of tens of well-defined classes — not hundreds of ad-hoc tags.
Step 1 / 3
VN/VRF isolation is macro-segmentation. Virtualize only when needed — do not use VN count as fake microseg.