<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: If all you have is a 2960 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-trustsec-enforcement-2960-switches/m-p/3185051#M25682</link>
    <description>&lt;P&gt;I believe the only 2960 only supports "Protected Port" and doesn't support PrivateVLAN fully.&lt;/P&gt;</description>
    <pubDate>Sat, 16 Sep 2017 18:47:56 GMT</pubDate>
    <dc:creator>Tim Glen</dc:creator>
    <dc:date>2017-09-16T18:47:56Z</dc:date>
    <item>
      <title>Cisco TrustSec Enforcement (2960 Switches)</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-trustsec-enforcement-2960-switches/m-p/3092124#M25671</link>
      <description>&lt;P&gt;Understand 2960 switches are able to perform classification (Cisco TrustSec Security Secure Tag )&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;For example&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have a PCI Server and non-PCI server (same VLAN) connect to same 2960 switch. &amp;nbsp;Is that possible to use Cisco TrustSec on 2960 Switch to control the access between the PCI server and non-PCI server?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards.,&lt;/P&gt;
&lt;P&gt;Eric&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 07:52:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-trustsec-enforcement-2960-switches/m-p/3092124#M25671</guid>
      <dc:creator>chong.eric</dc:creator>
      <dc:date>2019-03-11T07:52:55Z</dc:date>
    </item>
    <item>
      <title>Many 2960 switches are</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-trustsec-enforcement-2960-switches/m-p/3092125#M25672</link>
      <description>&lt;P&gt;Many 2960 switches are capable of Trustsec SGT &lt;SPAN style="text-decoration: line-through;"&gt;segmentation and enforcement&lt;/SPAN&gt;&amp;nbsp;correction - &lt;STRONG&gt;marking&lt;/STRONG&gt;. The complete matrix you should check can be found here:&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/dam/en/us/solutions/collateral/enterprise-networks/trustsec/platform-capability-matrix.pdf&lt;/P&gt;
&lt;P&gt;You can manually configure it or (more commonly) use something like ISE to dynamically assign SGTs based on endpoint identity.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;SGACLs would need to be on an upstream device that supports enforcement.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;(Thanks to Rob for pointing ot the enforcement distinction.)&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jul 2017 08:10:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-trustsec-enforcement-2960-switches/m-p/3092125#M25672</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-07-24T08:10:59Z</dc:date>
    </item>
    <item>
      <title>Checked the complete matrix</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-trustsec-enforcement-2960-switches/m-p/3092126#M25673</link>
      <description>&lt;P&gt;Checked the complete matrix from the URL you provided. &amp;nbsp;Looks like non of Cisco 2960 switches support SGT enforcement. &amp;nbsp;Can you please confirm?&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jul 2017 08:11:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-trustsec-enforcement-2960-switches/m-p/3092126#M25673</guid>
      <dc:creator>chong.eric</dc:creator>
      <dc:date>2017-07-24T08:11:00Z</dc:date>
    </item>
    <item>
      <title>Correct, the 2960 model</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-trustsec-enforcement-2960-switches/m-p/3092127#M25674</link>
      <description>&lt;P&gt;Correct, the 2960 model switches do not support enforcement.You'd have to enable enforcement upstream on a device that supports enforcement SGACL/SG Firewall.&lt;/P&gt;
&lt;P&gt;The 2960 switches do support trustsec SGT classfication, you'd have to use SXP to transport the SGT bindings to the device that will do the enforcement as the 2960's do not support inline tagging.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jul 2017 11:18:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-trustsec-enforcement-2960-switches/m-p/3092127#M25674</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2017-07-24T11:18:47Z</dc:date>
    </item>
    <item>
      <title>ok, back to my example </title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-trustsec-enforcement-2960-switches/m-p/3092128#M25675</link>
      <description>&lt;P&gt;ok, back to my example&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Is that possible to use Cisco TrustSec on 2960 Switch to control the access between the PCI server and non-PCI server?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I guess the answer is no. &amp;nbsp;Am I correct?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jul 2017 16:09:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-trustsec-enforcement-2960-switches/m-p/3092128#M25675</guid>
      <dc:creator>chong.eric</dc:creator>
      <dc:date>2017-07-26T16:09:12Z</dc:date>
    </item>
    <item>
      <title>If all you have is a 2960</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-trustsec-enforcement-2960-switches/m-p/3092129#M25676</link>
      <description>&lt;P&gt;If all you have is a 2960 then the answer is no.&lt;/P&gt;
&lt;P&gt;You could use private VLANs.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jul 2017 16:32:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-trustsec-enforcement-2960-switches/m-p/3092129#M25676</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-07-26T16:32:31Z</dc:date>
    </item>
    <item>
      <title>Re: If all you have is a 2960</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-trustsec-enforcement-2960-switches/m-p/3185051#M25682</link>
      <description>&lt;P&gt;I believe the only 2960 only supports "Protected Port" and doesn't support PrivateVLAN fully.&lt;/P&gt;</description>
      <pubDate>Sat, 16 Sep 2017 18:47:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-trustsec-enforcement-2960-switches/m-p/3185051#M25682</guid>
      <dc:creator>Tim Glen</dc:creator>
      <dc:date>2017-09-16T18:47:56Z</dc:date>
    </item>
    <item>
      <title>Re: If all you have is a 2960</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-trustsec-enforcement-2960-switches/m-p/3823128#M25687</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326046"&gt;@Marvin Rhoads&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;If all you have is a 2960 then the answer is no.&lt;/P&gt;
&lt;P&gt;You could use private VLANs.&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;ok, but if 2960 is connected to a 3850, can i&amp;nbsp;use TrustSec on 3850 to control the access between the PCI server and non-PCI server that they are on 2960 Switch?&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2019 17:25:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-trustsec-enforcement-2960-switches/m-p/3823128#M25687</guid>
      <dc:creator>Paolo Bratti</dc:creator>
      <dc:date>2019-03-20T17:25:55Z</dc:date>
    </item>
    <item>
      <title>Re: If all you have is a 2960</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-trustsec-enforcement-2960-switches/m-p/3823930#M25690</link>
      <description>Yes, if they are in different subnets and you force the SVI routing through the 3850.  To make this work the 3850 needs to know the SGT's of the destination and source, either through static SGT IP mappings or via SXP.  &lt;BR /&gt;&lt;BR /&gt;The 3850 needs to know the SGT's as they relate to IP's, and have SGACL relationships for the SGT's.</description>
      <pubDate>Thu, 21 Mar 2019 18:44:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-trustsec-enforcement-2960-switches/m-p/3823930#M25690</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2019-03-21T18:44:54Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco TrustSec Enforcement (2960 Switches)</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-trustsec-enforcement-2960-switches/m-p/3824201#M25694</link>
      <description>&lt;P&gt;i cant install this prm...(&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2019 07:36:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-trustsec-enforcement-2960-switches/m-p/3824201#M25694</guid>
      <dc:creator>Johnatan Dire</dc:creator>
      <dc:date>2019-03-22T07:36:07Z</dc:date>
    </item>
  </channel>
</rss>

