In a traditional campus, segmentation and policy are tied to network topology. You create VLANs, map each VLAN to a subnet and default gateway, and write IP-based access control lists to control traffic between subnets. If you want a user group available in several buildings, you stretch VLANs across trunks, which brings spanning tree, broadcast domains that grow and larger failure domains. Every switch is configured by hand, and ACLs grow into long lists of addresses that must change whenever addressing changes.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 5 more sections, 5 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.