<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Maximum SGT per Device. in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/maximum-sgt-per-device/m-p/3510146#M491107</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you veyr much for your answerJonothan, this iinformation is very useful. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 26 Sep 2017 16:28:28 GMT</pubDate>
    <dc:creator>ecanogut</dc:creator>
    <dc:date>2017-09-26T16:28:28Z</dc:date>
    <item>
      <title>Maximum SGT per Device.</title>
      <link>https://community.cisco.com/t5/network-access-control/maximum-sgt-per-device/m-p/3510144#M491053</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.33px; font-family: Helvetica;"&gt;Hello everyone&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.33px; font-family: Helvetica;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.33px; font-family: Helvetica;"&gt;In Admin guide says that even ISE supports 65,535 SGTs the maximum recommended is 4,000.&lt;SPAN class="Apple-converted-space"&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.33px; font-family: Helvetica;"&gt;The question is: when the devices (switches, routers, ASA, etc) download the environment data from ISE is there a limit depending on the device type on how many of the SGTs it can have on its table? &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.33px; font-family: Helvetica;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.33px; font-family: Helvetica;"&gt;Thanks in advanced. &lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Mar 2019 08:01:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/maximum-sgt-per-device/m-p/3510144#M491053</guid>
      <dc:creator>ecanogut</dc:creator>
      <dc:date>2019-03-11T08:01:13Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum SGT per Device.</title>
      <link>https://community.cisco.com/t5/network-access-control/maximum-sgt-per-device/m-p/3510145#M491075</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Emmanuel,&lt;/P&gt;&lt;P&gt;sorry for the delay.&lt;/P&gt;&lt;P&gt;if the platform can download/install a PAC and securely communicate with ISE then it will be able to download all the SGT's provisioned (up to a tested maximum of 4000).&lt;/P&gt;&lt;P&gt;Now, there may be limits with what you can do with them per platform. For example, the 3850 can enforce using 256 different destination SGTs at any one time. Also, the Cat4k can only enforce for 2000 DGTs for switched traffic.&lt;/P&gt;&lt;P&gt;But for downloading, you're good to go.&lt;/P&gt;&lt;P&gt;Regards, Jonothan.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Sep 2017 16:19:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/maximum-sgt-per-device/m-p/3510145#M491075</guid>
      <dc:creator>jeaves@cisco.com</dc:creator>
      <dc:date>2017-09-26T16:19:08Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum SGT per Device.</title>
      <link>https://community.cisco.com/t5/network-access-control/maximum-sgt-per-device/m-p/3510146#M491107</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you veyr much for your answerJonothan, this iinformation is very useful. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Sep 2017 16:28:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/maximum-sgt-per-device/m-p/3510146#M491107</guid>
      <dc:creator>ecanogut</dc:creator>
      <dc:date>2017-09-26T16:28:28Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum SGT per Device.</title>
      <link>https://community.cisco.com/t5/network-access-control/maximum-sgt-per-device/m-p/3711461#M491133</link>
      <description>&lt;P&gt;"But for downloading, you're good to go."&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does this mean you can exceed the 256 SGT Destination limit can be exceeded?&amp;nbsp; I'm trying to micro segment up to 1200 users in a residential dormitory type environment so 265 will easily be exceeded. &lt;/P&gt;</description>
      <pubDate>Sat, 22 Sep 2018 02:22:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/maximum-sgt-per-device/m-p/3711461#M491133</guid>
      <dc:creator>adschaef</dc:creator>
      <dc:date>2018-09-22T02:22:59Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum SGT per Device.</title>
      <link>https://community.cisco.com/t5/network-access-control/maximum-sgt-per-device/m-p/3711609#M491152</link>
      <description>An Idea for you to consider. You could use a single SGT for all students and have a deny ip SGACL in the matrix.  This would stop any student to student communication.  If you have a student that needs two devices talking to each other, you could break that student's devices out in to a new SGT.</description>
      <pubDate>Sun, 23 Sep 2018 02:47:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/maximum-sgt-per-device/m-p/3711609#M491152</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2018-09-23T02:47:16Z</dc:date>
    </item>
  </channel>
</rss>

