A tax assessor’s SD-Access design must isolate a new third-party appraisal SaaS VRF-style tenancy from staff while still tagging fine-grained roles inside the staff network. When is a new Virtual Network (VN) warranted instead of only adding an SGT inside an existing VN?
Select an answer to reveal the explanation.
Short Explanation
Picture city blocks (VNs) versus badge colors inside a block (SGTs). A whole new tenancy that needs its own routing neighborhood gets a VN; clerks versus managers in the same neighborhood get different SGT badges. Do not spawn a VN for every AD group or you drown in overlay sprawl.
Full Explanation
In SD-Access, Virtual Networks provide macro segmentation: separate overlay routing and policy domains for distinct tenancies or trust boundaries. Scalable Group Tags enforce micro-segmentation and group-based policy inside a VN. A third-party appraisal tenancy that must not share the staff overlay routing domain warrants a new VN, while role differences among staff are typically expressed with SGTs. Creating a VN per AD group or tying VN creation to underlay OSPF process IDs conflates macro and micro design.