<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: N2K used in TrustSec Solution in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/n2k-used-in-trustsec-solution/m-p/3572506#M493093</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Robert,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So the Nexus 2K FEXs do support TrustSec. When attached to a Nexus 5500/5600/6000, the FEX port can be configured on the N5K/N6K with a static Port to SGT. When attached to a N5K/6K or even a N7K, there is no configuration required for the FEX Uplinks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is one thing to remember, when attached to a N5K or an N6K the only classification is via Port SGT assignment. The N5K/N6K (and hence N2K attached to them) do not support IP-SGT, VLAN-SGT. Relative to what Keti said regarding NIF(Network Interface) ports, they do not need configuration as traffic will be tagged at the N5K/6K to which the FEX is attached. For HIF (Host) ports. The port is assigned an SGT and is configured on the N5K/N6K. Any traffic coming from that server will be tagged upon exiting the N5K or N6K.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The N5K/6K can enforce Trustsec policies for servers attached to the same FEX in the same VLAN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now if a N2K FEX is attached to a N7K, the N7K does NOT support a static SGT assignment on the FEX HIF port. In oreder to classify servers attached to a N2K FEX with an N7K as a parent, Static IP-SGT, Subnet-SGT (NX-OS 7.3 or later), or VLAN to SGT.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please also refer to the TrustSec Data Center Segmentation Design Guide on CCO at &lt;A href="http://www.cisco.com/c/dam/en/us/solutions/collateral/enterprise-networks/trustsec/trustsec-data-center-segmentation-guide.pdf" title="http://www.cisco.com/c/dam/en/us/solutions/collateral/enterprise-networks/trustsec/trustsec-data-center-segmentation-guide.pdf"&gt;http://www.cisco.com/c/dam/en/us/solutions/collateral/enterprise-networks/trustsec/trustsec-data-center-segmentation-guide.pdf &lt;SPAN style="color: #000000;"&gt;for more information.&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike Jessup&lt;/P&gt;&lt;P&gt;TrustSec TME&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 21 Jun 2016 00:51:34 GMT</pubDate>
    <dc:creator>mjessup</dc:creator>
    <dc:date>2016-06-21T00:51:34Z</dc:date>
    <item>
      <title>N2K used in TrustSec Solution</title>
      <link>https://community.cisco.com/t5/network-access-control/n2k-used-in-trustsec-solution/m-p/3572504#M493079</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In the TrustSec 5.3 guide there is no mention of the N2K being in the compatability guide. Does this mean that the N2K does not support all of the TrustSec features and thus cant be used i a Secure DC soultion?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-- &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Grace and Peace,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Robert E Roulhac Jr&lt;/P&gt;&lt;P&gt;Virtual Systems Engineer II&lt;/P&gt;&lt;P&gt;Cisco TSN (Technical Solutions Network)&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-email-small" href="mailto:rroulhac@cisco.com" target="_blank"&gt;rroulhac@cisco.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Office: 919.5745455&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Mar 2019 06:52:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/n2k-used-in-trustsec-solution/m-p/3572504#M493079</guid>
      <dc:creator>rroulhac</dc:creator>
      <dc:date>2019-03-11T06:52:38Z</dc:date>
    </item>
    <item>
      <title>Re: N2K used in TrustSec Solution</title>
      <link>https://community.cisco.com/t5/network-access-control/n2k-used-in-trustsec-solution/m-p/3572505#M493087</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;IP-SGT, Subnet-SGT, and VLAN-SGT are supported for FEX connected servers.&lt;/P&gt;&lt;P&gt;Port-SGT is not supported with FEX:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Port-SGT is not supported for FEX NIF ports&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Port-SGT is not support for servers connected to FEX HIF ports.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Inline SGT tagging is not supported for devices connected to FEX ports&lt;/P&gt;&lt;P&gt;SGACL enforcement is supported for FEX connected devices.&amp;nbsp; The SGACLs are downloaded to the SoC/ASIC which controls the ports where the FEX NIFs are connected.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Jun 2016 19:26:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/n2k-used-in-trustsec-solution/m-p/3572505#M493087</guid>
      <dc:creator>kilcreas</dc:creator>
      <dc:date>2016-06-20T19:26:15Z</dc:date>
    </item>
    <item>
      <title>Re: N2K used in TrustSec Solution</title>
      <link>https://community.cisco.com/t5/network-access-control/n2k-used-in-trustsec-solution/m-p/3572506#M493093</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Robert,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So the Nexus 2K FEXs do support TrustSec. When attached to a Nexus 5500/5600/6000, the FEX port can be configured on the N5K/N6K with a static Port to SGT. When attached to a N5K/6K or even a N7K, there is no configuration required for the FEX Uplinks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is one thing to remember, when attached to a N5K or an N6K the only classification is via Port SGT assignment. The N5K/N6K (and hence N2K attached to them) do not support IP-SGT, VLAN-SGT. Relative to what Keti said regarding NIF(Network Interface) ports, they do not need configuration as traffic will be tagged at the N5K/6K to which the FEX is attached. For HIF (Host) ports. The port is assigned an SGT and is configured on the N5K/N6K. Any traffic coming from that server will be tagged upon exiting the N5K or N6K.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The N5K/6K can enforce Trustsec policies for servers attached to the same FEX in the same VLAN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now if a N2K FEX is attached to a N7K, the N7K does NOT support a static SGT assignment on the FEX HIF port. In oreder to classify servers attached to a N2K FEX with an N7K as a parent, Static IP-SGT, Subnet-SGT (NX-OS 7.3 or later), or VLAN to SGT.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please also refer to the TrustSec Data Center Segmentation Design Guide on CCO at &lt;A href="http://www.cisco.com/c/dam/en/us/solutions/collateral/enterprise-networks/trustsec/trustsec-data-center-segmentation-guide.pdf" title="http://www.cisco.com/c/dam/en/us/solutions/collateral/enterprise-networks/trustsec/trustsec-data-center-segmentation-guide.pdf"&gt;http://www.cisco.com/c/dam/en/us/solutions/collateral/enterprise-networks/trustsec/trustsec-data-center-segmentation-guide.pdf &lt;SPAN style="color: #000000;"&gt;for more information.&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike Jessup&lt;/P&gt;&lt;P&gt;TrustSec TME&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Jun 2016 00:51:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/n2k-used-in-trustsec-solution/m-p/3572506#M493093</guid>
      <dc:creator>mjessup</dc:creator>
      <dc:date>2016-06-21T00:51:34Z</dc:date>
    </item>
  </channel>
</rss>

