Home / Podcasts / Episode 11
Tech Lounge Podcast · Episode 11

Microsegmentation with GPO

Published Nov 23 · Ehsan Emad

Episode Summary

In this episode, we dive into one of the most important innovations shaping modern data center architectures: Micro-Segmentation using GPO (Group Policy Option) in VXLAN-EVPN and NX-OS environments.
In this episode, we explain:
- The role of Group Policy Option (GPO) in enabling true micro-segmentation
- ESG, SGACL, and how policies are carried along with the traffic
- GPO architecture on NX-OS and the difference between Ingress vs. Egress enforcement
- Service Chaining, traffic redirection, and distributed security at the Leaf
- Capabilities, limitations, and the technical improvements in recent NX-OS releases
- The future of GPO and why it is becoming one of the key pillars of security in modern fabrics

Key Takeaways

  • Understand how GPO supports microsegmentation in VXLAN-EVPN and NX-OS environments.
  • Review ESG and SGACL concepts and how policy information is carried with traffic.
  • Understand ingress versus egress enforcement.
  • Review service chaining and traffic redirection.
  • Understand the stated capabilities, limitations and evolution of GPO.

Chapters

  1. Why GPO matters for microsegmentation
  2. ESG and SGACL
  3. Policy carriage with traffic
  4. Ingress versus egress enforcement
  5. Service chaining and redirection
  6. Capabilities and limitations
  7. Future of GPO

Detailed Notes

The episode focuses on Group Policy Option as a mechanism for distributed policy and microsegmentation.
It connects GPO with ESG, SGACL, enforcement location, service chaining and recent NX-OS improvements.

Speaker

Ehsan Emad