A regional planning commission is drowning in per-IP extended ACLs for municipal apps and wants a more scalable SD-Access alternative. Which approach best replaces that ACL sprawl?
Select an answer to reveal the explanation.
Short Explanation
Line ACLs that chase every IP are like rewriting the guest list every time someone changes desks. Group-based policy tags roles and apps, then allows or denies group-to-group. The commission maintains intent, not a novel-length ACL on every hop.
Full Explanation
Group-based policy in SD-Access uses SGTs to express access intent between user and application groups, dramatically reducing dependency on lengthy per-IP extended ACLs that churn with addressing changes. Policy scales with identity groups rather than individual addresses. Dumping traffic into VLAN 1 or cloning ACLs onto underlay P2P links does not provide an operable segmentation strategy.