← CCNP Enterprise: ENCOR core and operations
07 / 8 · 40 MIN

Segmentation and API security

Connect classification, enforcement, and trust to verifiable criteria.

Concept and mechanism

A security label supplies policy context rather than proving an outcome was enforced. In TrustSec, group identification needs policy definition and verification at enforcement points. Segmentation also does not remove endpoint and application protection needs: permitted flows can carry unwanted content, and local activity remains outside simple path control. Design should combine responsibilities and evidence appropriate to each layer. Avoid promising absolute prevention merely because a VRF, firewall, or group tag exists. Acceptance needs examples of authorized communication and attempts that should be denied.

Guided application

APIs have similar boundaries. In the scenario where an authenticated identity receives 403 for a change, review authorized scope instead of endlessly retrying a token or granting global privileges. HTTPS protects transport and authenticates the server through the validation used; it does not turn an unprivileged identity into an administrator. If RESTCONF fails after a server-name change, confirm identity and trust chain and correct configuration. Disabling validation removes a required guarantee. In a fictional remote-management exercise, validate new sessions from the administrative network, denial from other sources, and authorized recovery. Retain results by rule and source so an aggregate counter or old session is not presented as evidence for every case.

IN PRACTICE

An SGT was assigned; policy still needs to be observed permitting and denying intended flows.

Common pitfalls

Label as enforcement; HTTPS as authorization; repeated token as privilege correction; old session as a new-connection test.

Related topics: Architecture and surviving capacity · Virtualization, VRFs, and overlays · Switching and adjacency formation

Take this idea with you

Each control needs evidence matching its function.

Create account

Reference: RESTCONF protocol · 350-401 ENCOR v1.2, effective 2026-03-19; core component of CCNP Enterprise