<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Using TrustSec for Campus and Branch segmentation in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/using-trustsec-for-campus-and-branch-segmentation/m-p/3592387#M491078</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would highly recommend you watching Cisco Live presentations on TrustSec if you are just starting with the technology. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think what you are referring to is how you'll be able to propagate tags from branch to headquarters and vice versa.&lt;/P&gt;&lt;P&gt;Propagation of tags can be via data plane like you mentioned over VPN - dmvpn or getvpn etc. &lt;/P&gt;&lt;P&gt;If propagation via data plane is not possible then SXP allows you to achieve propagation in control plane by sending the mappings over a separate protocol.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 05 Mar 2018 19:39:36 GMT</pubDate>
    <dc:creator>umahar</dc:creator>
    <dc:date>2018-03-05T19:39:36Z</dc:date>
    <item>
      <title>Using TrustSec for Campus and Branch segmentation</title>
      <link>https://community.cisco.com/t5/network-access-control/using-trustsec-for-campus-and-branch-segmentation/m-p/3592386#M491059</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have a client that is looking to segment their network.&amp;nbsp; They were initially thinking either ACL's on their switches or using a FW.&amp;nbsp; However, after talking to them about ISE and TrustSec, they are interested in that solution.&amp;nbsp; The client is an international company, so they have a branch/campus network layout.&amp;nbsp; In researching how TrustSec works in this scenario, I found the following guide:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/dam/en/us/solutions/collateral/enterprise-networks/trustsec/branch-segmentation.pdf" style="font-size: 10pt;" title="https://www.cisco.com/c/dam/en/us/solutions/collateral/enterprise-networks/trustsec/branch-segmentation.pdf" target="_blank"&gt;https://www.cisco.com/c/dam/en/us/solutions/collateral/enterprise-networks/trustsec/branch-segmentation.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It mentions having the WAN connectivity being encrypted, but I also heard there is an encapsulation method that you can use instead.&amp;nbsp; However, I cannot find anything on the encapsulation method, how it works and what devices are required.&amp;nbsp; Issue we have at this client is even though their WAN links are connected with Cisco routers, they do not manage them.&amp;nbsp; So getting this provider to implement a VPN across the WAN links for TrustSec may not happen.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If someone can provide me that information, it would be appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Mar 2019 00:36:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/using-trustsec-for-campus-and-branch-segmentation/m-p/3592386#M491059</guid>
      <dc:creator>deyster94</dc:creator>
      <dc:date>2019-03-26T00:36:26Z</dc:date>
    </item>
    <item>
      <title>Re: Using TrustSec for Campus and Branch segmentation</title>
      <link>https://community.cisco.com/t5/network-access-control/using-trustsec-for-campus-and-branch-segmentation/m-p/3592387#M491078</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would highly recommend you watching Cisco Live presentations on TrustSec if you are just starting with the technology. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think what you are referring to is how you'll be able to propagate tags from branch to headquarters and vice versa.&lt;/P&gt;&lt;P&gt;Propagation of tags can be via data plane like you mentioned over VPN - dmvpn or getvpn etc. &lt;/P&gt;&lt;P&gt;If propagation via data plane is not possible then SXP allows you to achieve propagation in control plane by sending the mappings over a separate protocol.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Mar 2018 19:39:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/using-trustsec-for-campus-and-branch-segmentation/m-p/3592387#M491078</guid>
      <dc:creator>umahar</dc:creator>
      <dc:date>2018-03-05T19:39:36Z</dc:date>
    </item>
  </channel>
</rss>

