Disclosed are methods, controllers, and computer-readable media that explicitly
label data packets and interfaces as trusted or untrusted. The data packet labeling can occur at a centralized security hub or at the
enforcement site itself, i.e., at the interface to the trusted or untrusted region. The packet can be labeled with
metadata associated with the packet, and that
label can be carried through the transport of the packet to avoid overbroad or unnecessary security procedures. Further, a
network administrator can designate certain links as trusted or untrusted so that packets designated as trusted can be sent down trusted links, and untrusted traffic can be sent down untrusted links. Network resources are saved while traffic is better separated and allocated down links with
trustworthiness that is congruent with that of the packet.