PP129: Inline Segmentation – HPE Networking’s Easy Button for Zero Trust (Sponsored)
The Fat Pipe - All Packet Pushers Pods
October 6, 2026
Sponsor HPE Networking comes to Packet Protector to talk about zero trust inline segmentation. This is a feature available in Juniper switches that can segment LAN traffic using group policy tags without the complexity associated with VXLAN or other segmentation mechanisms.
Speakers JJ Javush, Abhi Shamsudar, Wes Purvis, Drew Coneery-Murray
TopicsTechnology
JJ Javush (0:06)
Hey, everybody, welcome to Packet Protector, the podcast at the intersection of networking and security. I'm Juniper JJ Javush here with Drew Connery-Murray. Today, we've got a sponsored show with HPE Networking to learn about Zero Trust inline segmentation.
This is a feature in all of the Juniper switches that can segment LAN traffic using group policy tags without the complexity of associated VXLAN and other segmentation mechanics. On today's show, we're going to dig into how inline segmentation works, some common use cases, how it compares to other segmentation options that are out there, and how it can support our broader Zero Trust initiatives. Our guests today from HPE Networking are Abhi Shamsudar and Wes Purvis, both Senior Directors of Product Management. Hi, guys.
Abhi Shamsudar (0:50)
Hey, Tute.
Wes Purvis (0:51)
Hello, Tute and Tute.
Drew Coneery-Murray (0:52)
Yeah, so welcome to the podcast. And we are going to be talking about segmentation, so let's just start with the typical ways that you might segment LAN traffic, and then we'll contrast that with what we're going to talk about inline segmentation.
Abhi Shamsudar (1:05)
Traditionally, segmentation has been a function of you having the ability to write access lists, and in the wireless world, we've done WXLAN policies. All of them eventually going down to a part of assigning some form of a role to a device, and then having IP protocol on the right hand side, and a combination of all of those.
And being able to segment traffic, which is primarily, have always been traditionally inter-VLAN. Inter-VLAN has always been an open function, talking very strictly, very traditional functions. You write ACLs.
Unless you start doing Mac-to-Mac ACLs, then if, which is not scalable, anything inter-VLAN has always been a function of, you know, some form of tagging to prevent tag-to-tag conversation. But, you know, it has served us well. Until IP spaces have started exploding, you can't keep up with the amount of IP subminutes you create. Hence, IP, the number of access lists grow, and then searches run out of TCAM, and then problems start to grow. So that's essentially a quick form of, it has served us well, but I think we need to now step into the new future.
Drew Coneery-Murray (2:35)
So are we talking about, when I think of, you know, micro-segmentation particularly at the network level, I tend to think EVP and VXLAN, is that what you're talking about here?
Abhi Shamsudar (2:45)
EVP and VXLAN is one way to do it. I think that's a very fair question, because EVP and VXLAN always comes in the picture. Whenever you think of tags, or group-based tags, or GDP as they're called, and EVP and VXLAN comes into picture, because these group-based tags are embedded into the VXLAN header. The policy locally on a given device by itself does not need EVP and VXLAN at any given point in time. VXLAN comes into picture every time you want to do percolation of these tags, because just one device knowing about the tags is not good enough. We need the rest of the devices on the network to also be aware of the tags. And that's where VXLAN comes into picture, wherein the tag itself is embedded as part of the VXLAN header. That means any packet that's coming in comes into the switch, and gets its tag in some form or fashion.
Let's say, you know, a dynamic, static, whatever ways they are. And then once they're moving towards the destination, that tag is also embedded as part of the VXLAN header. Now the traffic passes all the way to the destination. Now only at the destination, you finally have the complete picture. You have the source tag as part of the VXLAN header. You have the destination tag because that is locally learnt at the destination. Then you decide to either drop the packet or allow the packet. This is generally called egress enforcement, because you're not implementing this function at the ingress, but now you're... And that's where VXLAN comes into picture.
That's a part where, you know, that's been done in the last three, four years. That's every time somebody said a micro segmentation, we said, okay, go that out of EDP and VXLAN, because, you know, VXLAN was standards based and percolation can only happen over VXLAN. That also meant if you have a small network, you know, you have five switches, ten switches in a store, you know, 15 APs or five switches in a store, or even medium branches, you know, 20 to 30 switches, some 50 APs. All of them, in spite of being a simple network, where even in the store LAN that I was just talking about a retail function, the switches and the APs probably did only L2 functions.
29 more minutes of transcript below
Thousands of transcripts fetched by people building searchable podcast archives
Fetch the whole transcript
The demo key returns a sample episode in full, no card needed:
curl -H "x-api-key: pt_demo" \
https://spoken.md/transcripts/1000651996090Markdown with the speakers named, for your notes, your knowledge base, or anything that makes HTTP calls.
From $0.10 per transcript. No subscription. Credits never expire. Prices exclude VAT, added at checkout for EU customers. Not what you expected? Email us within 14 days with 20 or fewer credits used and we refund the pack in full.
Using your own key:
curl -H "x-api-key: YOUR_KEY" \
https://spoken.md/transcripts/1000793526027