A municipal zero-trust initiative needs microsegmentation with group tags and policy inside an existing EVPN-VXLAN VNI rather than creating a new VNI per tier. Which Juniper data-center security approach fits that goal?
Select an answer to reveal the explanation.
Short Explanation
GBP is name tags on badges plus rules about who can talk to whom—inside the same big room (VNI). You do not need a new room for every job title. CoS marks priority; it is not microseg policy.
Full Explanation
Group-Based Policy provides microsegmentation in EVPN-VXLAN fabrics by assigning endpoints to groups and enforcing allow/deny (and related) policies between those groups, including within a VNI. That avoids exploding VNI counts solely to separate application tiers. Underlay CoS, disabling MAC learning, or reverting to broad VLAN stitching do not deliver GBP-style group policy.