Which component of Cisco SD-Access integrates with Cisco DNA Center to perform policy segmentation and enforcement through the use of security group access control lists and security group tags?
Cisco Identity Services Engine is the SD-Access component that integrates with Cisco DNA Center to provide identity-based policy, Security Group Tags, and Security Group ACL policy enforcement. Cisco SD-Access uses Cisco TrustSec technology concepts for group-based policy, but ISE is the actual policy and identity services platform that integrates with Cisco DNA Center. DNA Center automates fabric deployment and policy orchestration, while ISE provides endpoint identity, group assignment, scalable group information, and policy authorization. SGACLs define permitted or denied communication between security groups, and SGTs classify users or endpoints into those groups. APIC-EM is not the SD-Access policy platform. Cisco Network Data Platform supports analytics and assurance functions, not identity policy enforcement. Cisco TrustSec is the underlying policy technology, but the question asks for the component that integrates with Cisco DNA Center. Therefore, the verified answer is Cisco Identity Services Engine. In design terms, ISE should be planned as a critical policy-plane dependency with redundancy, pxGrid integration, RADIUS services, and consistent scalable group policy design.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit