A fleet garage auditor asks for evidence of SD-Access segmentation intent without receiving live ISE policy tree exports. What documentation artifact best captures VN and SGT design for civic compliance?
Select an answer to reveal the explanation.
Short Explanation
Auditors want the zoning map, not the locksmith’s keyring. A VN/SGT matrix shows which civic roles share a network neighborhood and which badges get which rules—without handing over live ISE trees or RADIUS secrets. Underlay MTU sheets and VXLAN pcaps do not explain segmentation intent.
Full Explanation
Civic compliance reviews need a clear record of macro and micro segmentation intent: which Virtual Networks exist, which Scalable Group Tags map to roles, and how trust boundaries align to policy. Publishing VN/SGT design matrices satisfies that need without exposing live ISE policy trees or credentials. Packet captures and underlay MTU tables are operational artifacts, not segmentation design documentation. Keeping intent documents current also helps operators avoid undocumented CLI exceptions.