<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Trustsec query in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/trustsec-query/m-p/2385331#M105757</link>
    <description>&lt;P&gt;&amp;nbsp; Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm having trouble figuring out exactly what I need to do for my trustec solution. I have the following topology:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISE 1.2&lt;/P&gt;&lt;P&gt;Cisco 2960-X - 2 x Cisco 7004 (each has 3 vdc - dist, core and DC) - Cisco 5548&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have configured each vdc on all the 7004s as a seed devices (probably do not need that many). All devices have been configured on ISE.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am running SXP between the 2960-X and the distribution vdc on the 7004 - that all seems fine as my SXP devices all show as connected.&lt;/P&gt;&lt;P&gt;My cts environment data appears to be correct in that I am seeing all my seed devices and my SGTs are being downloaded from ISE. The cts pac is also correct. I am seeing my SGACLs being downloaded from ISE as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The two problems I see are:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unless I manually configure the sgt-map on the 7004 I do not see the mappings. I'm obviously missing something configuration wise here but for all my trolling through trustsec documents I can't find what.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I do a show cts role-based policy I see the source and destination groups being associated but I don't see the SGACL association - for example:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sgt:7(Student_SG)&lt;/P&gt;&lt;P&gt;dgt:3(Test_SG)&amp;nbsp; rbacl:Deny IP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; deny ip&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;whereas I would expect to see this SGACL:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rbacl:Test_SGACL&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; permit tcp dst eq 80&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; permit tcp dst eq 443&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; deny all&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All the documentation I read seems to refer to having a 6500 switch as the next hop from the access layer whereas in my case it is a Nexus 7004 and the commands for the 6500 series do not all have an equivalent on the 7004.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Basically I need to know about enforcement on the 7004.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anyone know of any links I can look at to try and sort out what I need to do to complete this configuration?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alan&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 04:10:29 GMT</pubDate>
    <dc:creator>ALAN MURRAY</dc:creator>
    <dc:date>2019-03-11T04:10:29Z</dc:date>
    <item>
      <title>Trustsec query</title>
      <link>https://community.cisco.com/t5/network-access-control/trustsec-query/m-p/2385331#M105757</link>
      <description>&lt;P&gt;&amp;nbsp; Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm having trouble figuring out exactly what I need to do for my trustec solution. I have the following topology:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISE 1.2&lt;/P&gt;&lt;P&gt;Cisco 2960-X - 2 x Cisco 7004 (each has 3 vdc - dist, core and DC) - Cisco 5548&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have configured each vdc on all the 7004s as a seed devices (probably do not need that many). All devices have been configured on ISE.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am running SXP between the 2960-X and the distribution vdc on the 7004 - that all seems fine as my SXP devices all show as connected.&lt;/P&gt;&lt;P&gt;My cts environment data appears to be correct in that I am seeing all my seed devices and my SGTs are being downloaded from ISE. The cts pac is also correct. I am seeing my SGACLs being downloaded from ISE as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The two problems I see are:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unless I manually configure the sgt-map on the 7004 I do not see the mappings. I'm obviously missing something configuration wise here but for all my trolling through trustsec documents I can't find what.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I do a show cts role-based policy I see the source and destination groups being associated but I don't see the SGACL association - for example:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sgt:7(Student_SG)&lt;/P&gt;&lt;P&gt;dgt:3(Test_SG)&amp;nbsp; rbacl:Deny IP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; deny ip&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;whereas I would expect to see this SGACL:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rbacl:Test_SGACL&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; permit tcp dst eq 80&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; permit tcp dst eq 443&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; deny all&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All the documentation I read seems to refer to having a 6500 switch as the next hop from the access layer whereas in my case it is a Nexus 7004 and the commands for the 6500 series do not all have an equivalent on the 7004.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Basically I need to know about enforcement on the 7004.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anyone know of any links I can look at to try and sort out what I need to do to complete this configuration?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alan&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 04:10:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trustsec-query/m-p/2385331#M105757</guid>
      <dc:creator>ALAN MURRAY</dc:creator>
      <dc:date>2019-03-11T04:10:29Z</dc:date>
    </item>
    <item>
      <title>Re: Trustsec query</title>
      <link>https://community.cisco.com/t5/network-access-control/trustsec-query/m-p/3353782#M105796</link>
      <description>&lt;P&gt;Hello Alan,&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Trustsec query&lt;BR /&gt; &lt;/STRONG&gt;Check if you have cisco secure ACS , dynamic ARP inspection or DHCP snooping available on you cisco NX-OS device .&lt;/P&gt;</description>
      <pubDate>Fri, 23 Mar 2018 07:44:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trustsec-query/m-p/3353782#M105796</guid>
      <dc:creator>jkilleda</dc:creator>
      <dc:date>2018-03-23T07:44:51Z</dc:date>
    </item>
  </channel>
</rss>

