<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE Inline Posture and SGT in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-inline-posture-and-sgt/m-p/2335370#M148786</link>
    <description>&lt;P&gt;ISE Experts,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm doing research preparing for an SGT deployment.&lt;/P&gt;&lt;P&gt;We have Cisco ASA for VPN and iPEP for Posture enforecement.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The questions are:&lt;/P&gt;&lt;P&gt;1) Does iPEP support SGT?&lt;/P&gt;&lt;P&gt;2) Can I utilize SGT for VPN users?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Val&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 03:56:22 GMT</pubDate>
    <dc:creator>valrerod</dc:creator>
    <dc:date>2019-03-11T03:56:22Z</dc:date>
    <item>
      <title>ISE Inline Posture and SGT</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-inline-posture-and-sgt/m-p/2335370#M148786</link>
      <description>&lt;P&gt;ISE Experts,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm doing research preparing for an SGT deployment.&lt;/P&gt;&lt;P&gt;We have Cisco ASA for VPN and iPEP for Posture enforecement.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The questions are:&lt;/P&gt;&lt;P&gt;1) Does iPEP support SGT?&lt;/P&gt;&lt;P&gt;2) Can I utilize SGT for VPN users?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Val&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:56:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-inline-posture-and-sgt/m-p/2335370#M148786</guid>
      <dc:creator>valrerod</dc:creator>
      <dc:date>2019-03-11T03:56:22Z</dc:date>
    </item>
    <item>
      <title>ISE Inline Posture and SGT</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-inline-posture-and-sgt/m-p/2335371#M148814</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="text-align: justify;"&gt;The Cisco&amp;nbsp; TrustSec (CTS) architecture secures networks by establishing domains of&amp;nbsp; trusted network devices. Once a network device authenticates with the&amp;nbsp; network, the communication on the links between devices in the cloud is&amp;nbsp; secured with a combination of encryption, message integrity checks, and&amp;nbsp; replay protection mechanisms.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="text-align: justify;"&gt;CTS&amp;nbsp; use the user and device identification information acquired during the&amp;nbsp; authentication phase to classify packets as they enter the network. CTS&amp;nbsp; maintains classification of each packet or frame by tagging it with a&amp;nbsp; security group tag (SGT) on ingress to the network so that it can be&amp;nbsp; identified for applying security and other policy criteria along the&amp;nbsp; data path. The tags allow network intermediaries such as switches and&amp;nbsp; firewalls to enforce access control policy based on the classification. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="text-align: justify;"&gt;&lt;STRONG&gt;Please&amp;nbsp; check the below links which may be helpful for you in configurations:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Link-1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/security/ise/1.1/user_guide/ise_sga_pol.pdf"&gt;http://www.cisco.com/en/US/docs/security/ise/1.1/user_guide/ise_sga_pol.pdf&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Sep 2013 16:52:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-inline-posture-and-sgt/m-p/2335371#M148814</guid>
      <dc:creator>aqjaved</dc:creator>
      <dc:date>2013-09-30T16:52:53Z</dc:date>
    </item>
    <item>
      <title>Using Ipep for SGT probably</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-inline-posture-and-sgt/m-p/2335372#M148873</link>
      <description>&lt;P&gt;Using Ipep for SGT probably is not a use case that we've seen so far and i cant be sure if it was tested.&lt;/P&gt;&lt;P&gt;However with ASA 9.2 you can enforce SGT based policies on the VPN users without needing an Ipep.&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/support/docs/security/adaptive-security-appliance-asa-software/117694-config-asa-00.html&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Gurudatt&lt;/P&gt;&lt;P&gt;ISE Escalation engineer | CCIE#28227&lt;/P&gt;&lt;P&gt;Cisco systems.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2014 09:21:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-inline-posture-and-sgt/m-p/2335372#M148873</guid>
      <dc:creator>Gurudatt Pai</dc:creator>
      <dc:date>2014-06-04T09:21:55Z</dc:date>
    </item>
    <item>
      <title>Here , in this scenario , I</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-inline-posture-and-sgt/m-p/2335373#M148949</link>
      <description>&lt;P&gt;Here , in this scenario , I think the PSN would support SGT over ASA, not ipep&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jun 2014 09:26:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-inline-posture-and-sgt/m-p/2335373#M148949</guid>
      <dc:creator>Saurav Lodh</dc:creator>
      <dc:date>2014-06-05T09:26:38Z</dc:date>
    </item>
    <item>
      <title>Hi,As we know that SGT is</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-inline-posture-and-sgt/m-p/2335374#M148993</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;Hi,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;As we know that SGT is Cisco-proprietary tagging system.&lt;BR /&gt;we just need to confirm before&amp;nbsp;deployment, does NAD devices support SGT ?&lt;BR /&gt;so with ASA 9.2 you can use SGT for VPN users.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;As per my understanding iPEP is another part it would not have any issue&amp;nbsp;&lt;BR /&gt;with SGT enforcement policies.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jun 2014 11:46:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-inline-posture-and-sgt/m-p/2335374#M148993</guid>
      <dc:creator>abwahid</dc:creator>
      <dc:date>2014-06-05T11:46:38Z</dc:date>
    </item>
    <item>
      <title>Ipep would not be needed if</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-inline-posture-and-sgt/m-p/2335375#M149058</link>
      <description>&lt;P&gt;Ipep would not be needed if you use the tech note i pointed too. More over ,Ipep was a solution that was needed for VPN scenarios when ASA was not capable of supporting COA. Now with 9.2 since we do and this architecture is a more elegant solution than adding another hop (provided you're in Routed mode).&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jun 2014 04:46:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-inline-posture-and-sgt/m-p/2335375#M149058</guid>
      <dc:creator>Gurudatt Pai</dc:creator>
      <dc:date>2014-06-10T04:46:56Z</dc:date>
    </item>
  </channel>
</rss>

