<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Subnet/IP to SGT tagging on NX-OS in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/subnet-ip-to-sgt-tagging-on-nx-os/m-p/3762708#M25060</link>
    <description>&lt;P&gt;Sure, network devices only enforce when they are told to enforce.&lt;/P&gt;
&lt;P&gt;The N7k is told to enforce by using the following commands:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;(config)# cts role-based enforcement&lt;BR /&gt;&lt;BR /&gt;(config)# vrf context x&lt;BR /&gt;&amp;nbsp; cts role-based enforcement&lt;BR /&gt;&lt;BR /&gt;(config)# vlan y&lt;BR /&gt;&amp;nbsp; cts role-based enforcement&lt;/P&gt;</description>
    <pubDate>Thu, 13 Dec 2018 09:04:25 GMT</pubDate>
    <dc:creator>jeaves@cisco.com</dc:creator>
    <dc:date>2018-12-13T09:04:25Z</dc:date>
    <item>
      <title>Subnet/IP to SGT tagging on NX-OS</title>
      <link>https://community.cisco.com/t5/network-access-control/subnet-ip-to-sgt-tagging-on-nx-os/m-p/3754354#M25057</link>
      <description>&lt;P&gt;Hi team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a case where SGT tagging based on IP/subnet to SGT map is needed on N7K (M3 LC) without enforcement active. Traffic that needs to be tagged can enter nexus:&lt;/P&gt;
&lt;P&gt;- via untrusted access portchannel - no SVI for this specific VLAN, packets need to be tagged and are send to another device where they are already part of trusted domain,&lt;/P&gt;
&lt;P&gt;- via untrusted access or trunk port for a specific VLAN that has SVI configured.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For both cases IP/subnet to SGT mapping is configured (pushed via ISE) but the tagging is not happening. Is there any limitation for this or any special step to take to do this marking?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards,&lt;/P&gt;
&lt;P&gt;Michal&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Nov 2018 13:42:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/subnet-ip-to-sgt-tagging-on-nx-os/m-p/3754354#M25057</guid>
      <dc:creator>Michal Olsovsky</dc:creator>
      <dc:date>2018-11-28T13:42:27Z</dc:date>
    </item>
    <item>
      <title>Re: Subnet/IP to SGT tagging on NX-OS</title>
      <link>https://community.cisco.com/t5/network-access-control/subnet-ip-to-sgt-tagging-on-nx-os/m-p/3761884#M25058</link>
      <description>&lt;P&gt;When pushing mappings from ISE you can use SSH or SXP but the mapping always gets placed at the VRF level.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The N7K MUST have an SVI on the VLAN if using IP-SGT learnt via SXP (or) SSH from ISE (or) CLI on a particular VRF [So when mapping resides in the VRF]&lt;/LI&gt;
&lt;LI&gt;If N7K is L2 only then create an SVI w/o IP to be able to utilize the SXP or SSH mappings from ISE or the CLI mappings from the VRF&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Wed, 12 Dec 2018 11:57:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/subnet-ip-to-sgt-tagging-on-nx-os/m-p/3761884#M25058</guid>
      <dc:creator>jeaves@cisco.com</dc:creator>
      <dc:date>2018-12-12T11:57:12Z</dc:date>
    </item>
    <item>
      <title>Re: Subnet/IP to SGT tagging on NX-OS</title>
      <link>https://community.cisco.com/t5/network-access-control/subnet-ip-to-sgt-tagging-on-nx-os/m-p/3762664#M25059</link>
      <description>&lt;P&gt;Hi, thanks. These conditions are clear however is there a way to do the SGT marking without activating the enforcement?&lt;/P&gt;</description>
      <pubDate>Thu, 13 Dec 2018 08:26:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/subnet-ip-to-sgt-tagging-on-nx-os/m-p/3762664#M25059</guid>
      <dc:creator>Michal Olsovsky</dc:creator>
      <dc:date>2018-12-13T08:26:19Z</dc:date>
    </item>
    <item>
      <title>Re: Subnet/IP to SGT tagging on NX-OS</title>
      <link>https://community.cisco.com/t5/network-access-control/subnet-ip-to-sgt-tagging-on-nx-os/m-p/3762708#M25060</link>
      <description>&lt;P&gt;Sure, network devices only enforce when they are told to enforce.&lt;/P&gt;
&lt;P&gt;The N7k is told to enforce by using the following commands:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;(config)# cts role-based enforcement&lt;BR /&gt;&lt;BR /&gt;(config)# vrf context x&lt;BR /&gt;&amp;nbsp; cts role-based enforcement&lt;BR /&gt;&lt;BR /&gt;(config)# vlan y&lt;BR /&gt;&amp;nbsp; cts role-based enforcement&lt;/P&gt;</description>
      <pubDate>Thu, 13 Dec 2018 09:04:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/subnet-ip-to-sgt-tagging-on-nx-os/m-p/3762708#M25060</guid>
      <dc:creator>jeaves@cisco.com</dc:creator>
      <dc:date>2018-12-13T09:04:25Z</dc:date>
    </item>
    <item>
      <title>Re: Subnet/IP to SGT tagging on NX-OS</title>
      <link>https://community.cisco.com/t5/network-access-control/subnet-ip-to-sgt-tagging-on-nx-os/m-p/3762717#M25061</link>
      <description>&lt;P&gt;The question is will Nexus do SGT marking without active enforcement? This means only SGT maps configured without any enforcement activated.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Dec 2018 09:08:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/subnet-ip-to-sgt-tagging-on-nx-os/m-p/3762717#M25061</guid>
      <dc:creator>Michal Olsovsky</dc:creator>
      <dc:date>2018-12-13T09:08:47Z</dc:date>
    </item>
    <item>
      <title>Re: Subnet/IP to SGT tagging on NX-OS</title>
      <link>https://community.cisco.com/t5/network-access-control/subnet-ip-to-sgt-tagging-on-nx-os/m-p/3762728#M25062</link>
      <description>&lt;P&gt;Yes, our network devices (including the N7k) can classify/mark without enforcing.&lt;/P&gt;
&lt;P&gt;Classification/marking occurs when there is a mapping present (dynamic, static, from SXP). Enforcement only occurs if the enforcement commands are present and required policy has been downloaded.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Dec 2018 09:18:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/subnet-ip-to-sgt-tagging-on-nx-os/m-p/3762728#M25062</guid>
      <dc:creator>jeaves@cisco.com</dc:creator>
      <dc:date>2018-12-13T09:18:28Z</dc:date>
    </item>
    <item>
      <title>Re: Subnet/IP to SGT tagging on NX-OS</title>
      <link>https://community.cisco.com/t5/network-access-control/subnet-ip-to-sgt-tagging-on-nx-os/m-p/3762816#M25063</link>
      <description>&lt;P&gt;Thanks for the reply.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In our setup we have N7k (NX-OS 8.3.1) registered to ISE and envi-data &amp;amp; policies downloaded successfully. IP to SGT mappings are correctly pushed from ISE and present in config and no enforcement is active. We have 1 VLAN with active SVI (default vrf), mapping for this VLAN/subnet is present in the SGT-map and the traffic is coming to N7K over untrusted trunk port (no cts manual) however the traffic is leaving the N7K unmarked (SGT 0). Other traffic that is passing the N7K already marked is keeping the marking so the boundary interfaces are fine. Is there anything else needed to have marking active?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Dec 2018 10:10:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/subnet-ip-to-sgt-tagging-on-nx-os/m-p/3762816#M25063</guid>
      <dc:creator>Michal Olsovsky</dc:creator>
      <dc:date>2018-12-13T10:10:33Z</dc:date>
    </item>
    <item>
      <title>Re: Subnet/IP to SGT tagging on NX-OS</title>
      <link>https://community.cisco.com/t5/network-access-control/subnet-ip-to-sgt-tagging-on-nx-os/m-p/3762870#M25064</link>
      <description>&lt;P&gt;Can you try the following independently:&lt;/P&gt;
&lt;P&gt;a) Manually adding the mapping under the VLAN (rather than the VRF).&lt;/P&gt;
&lt;P&gt;b) &lt;SPAN style="caret-color: #000000; color: #000000; font-family: Ayuthaya; font-size: 14.666666984558105px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; text-decoration: none; display: inline !important; float: none;"&gt;Enable &lt;/SPAN&gt;&lt;SPAN style="caret-color: #000000; color: #000000; font-family: inherit !important; font-size: inherit !important; font-style: inherit !important; font-variant-caps: inherit !important; font-weight: inherit !important; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; text-decoration: none; background-color: #ffee94 !important; display: inline !important; position: static !important; margin: 0px !important; padding: 0px !important; opacity: 1 !important; float: inherit !important; font-stretch: inherit !important; line-height: inherit !important; background-position: initial initial !important; background-repeat: initial initial !important;"&gt;DAI&lt;/SPAN&gt;&lt;SPAN style="caret-color: #000000; color: #000000; font-family: Ayuthaya; font-size: 14.666666984558105px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; text-decoration: none; display: inline !important; float: none;"&gt; (ip arp inspection vlan &amp;lt;&amp;gt;) on the VLAN and on the corresponding incoming interfaces (ip arp inspection trust)&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Dec 2018 10:57:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/subnet-ip-to-sgt-tagging-on-nx-os/m-p/3762870#M25064</guid>
      <dc:creator>jeaves@cisco.com</dc:creator>
      <dc:date>2018-12-13T10:57:26Z</dc:date>
    </item>
    <item>
      <title>Re: Subnet/IP to SGT tagging on NX-OS</title>
      <link>https://community.cisco.com/t5/network-access-control/subnet-ip-to-sgt-tagging-on-nx-os/m-p/3763667#M25065</link>
      <description>&lt;P&gt;Thanks for reply. I will try both options and report back.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Dec 2018 11:09:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/subnet-ip-to-sgt-tagging-on-nx-os/m-p/3763667#M25065</guid>
      <dc:creator>Michal Olsovsky</dc:creator>
      <dc:date>2018-12-14T11:09:36Z</dc:date>
    </item>
  </channel>
</rss>

