Compared with maintaining traditional per-IP or per-port ACL sprawl on every leaf, what operational benefit does GBP microsegmentation provide for the municipal fabric?
Select an answer to reveal the explanation.
Short Explanation
Chasing every IP with a new ACL line is whack-a-mole. GBP says “cameras” and “finance” once, then endpoints inherit the club rules as they move. That is how policy stays sane at fabric scale.
Full Explanation
Group-based policy abstracts endpoints into groups so allow/deny intent is written once per group relationship instead of rewriting host-specific ACLs wherever workloads attach. That improves operational scale for east-west controls as servers move across leaves. GBP still affects forwarding decisions and is not limited to Internet edge use cases.