A security engineer is designing a secure network access solution for a new data center that hosts critical applications. The design must ensure that only authorized servers can communicate with each other, minimizing the attack surface even if a server is compromised. Traditional VLANs are deemed insufficient due to flat access control capabilities within a VLAN. Which approach using Cisco technologies would best achieve this granular segmentation and policy enforcement within the data center?
- AConfiguring Private VLANs (PVLANs) to isolate servers within a broadcast domain.
- BDeploying Cisco TrustSec with Security Group Tags (SGTs) and Security Group Access Control Lists (SGACLs).
- CImplementing a large number of micro-VLANs for each server.
- DUtilizing Port Security on all server-facing switch ports.
Show answer & explanationAnswer & explanation
Correct answer: B. Deploying Cisco TrustSec with Security Group Tags (SGTs) and Security Group Access Control Lists (SGACLs).
Cisco TrustSec with SGTs and SGACLs provides identity-based micro-segmentation, allowing for granular control over server-to-server communication based on security group membership, independent of network topology. This significantly reduces the attack surface. Micro-VLANs are complex and scale poorly, Port Security is for MAC address control, and PVLANs offer isolation within a broadcast domain but not dynamic identity-based policy enforcement across the data center.
Why the other options are wrong
- A. PVLANs isolate ports within a VLAN, preventing direct communication between specified ports, but they are not identity-based and can become complex for a large number of servers with dynamic communication needs.
- C. Implementing many micro-VLANs is complex to manage, does not provide identity-based control, and still suffers from flat access within a VLAN.
- D. Port Security binds MAC addresses to ports, preventing unauthorized devices from connecting, but does not provide granular server-to-server communication control based on identity.
Cisco TrustSec Micro-segmentation
A security architecture that uses Security Group Tags (SGTs) to classify network traffic based on user or device identity, enabling granular, identity-based policy enforcement (SGACLs) for micro-segmentation.
- Reduces attack surface by limiting lateral movement.
- Policies are identity-based, not IP-based.
- Simplifies network segmentation management.
Memory trick: For critical data, tag and segment every server based on its role, not just its location.