<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TrustSec SGT Binding Priority in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/trustsec-sgt-binding-priority/m-p/3568370#M494133</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you, Jonathan.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 04 May 2017 16:39:12 GMT</pubDate>
    <dc:creator>derrick.ray1</dc:creator>
    <dc:date>2017-05-04T16:39:12Z</dc:date>
    <item>
      <title>TrustSec SGT Binding Priority</title>
      <link>https://community.cisco.com/t5/network-access-control/trustsec-sgt-binding-priority/m-p/3568368#M494089</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 10pt; font-family: calibri, verdana, arial, sans-serif;"&gt;I had always thought that CTS binding priority was the same throughout TrustSec until recently I discovered that isn't true. Below is the SGT Binding priority that I have always worked with.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 168.75px; font-family: Calibri; font-size: 11.0pt;"&gt;&lt;SPAN style="font-family: calibri, verdana, arial, sans-serif; color: #000000; font-size: 10pt;"&gt;&lt;SPAN style="font-weight: bold;"&gt;1.VLAN&lt;/SPAN&gt;- Bindings learned from snooped ARP packets on a VLAN that has VLAN-SGT mapping configured&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 168.75px; font-family: Calibri; font-size: 11.0pt;"&gt;&lt;SPAN style="font-family: calibri, verdana, arial, sans-serif; color: #000000; font-size: 10pt;"&gt;&lt;SPAN style="font-weight: bold;"&gt;2.CLI&lt;/SPAN&gt;- Address bindings configured using the IP_SGT form of the "cts role-based sgt-map" global configuration command&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 168.75px; font-family: Calibri; font-size: 11.0pt;"&gt;&lt;SPAN style="font-family: calibri, verdana, arial, sans-serif; color: #000000; font-size: 10pt;"&gt;&lt;SPAN style="font-weight: bold;"&gt;3.Layer 3 Interface&lt;/SPAN&gt;- Bindings added du to FIB forwarding entries that have paths through one or more interfaces with consistent L3IF-SGT mapping or Identity Port Mapping on routed ports.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 168.75px; font-family: Calibri; font-size: 11.0pt;"&gt;&lt;SPAN style="font-family: calibri, verdana, arial, sans-serif; color: #000000; font-size: 10pt;"&gt;&lt;SPAN style="font-weight: bold;"&gt;4.SXP&lt;/SPAN&gt;- Bindings learned from SXP peers&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 168.75px; font-family: Calibri; font-size: 11.0pt;"&gt;&lt;SPAN style="font-family: calibri, verdana, arial, sans-serif; color: #000000; font-size: 10pt;"&gt;&lt;SPAN style="font-weight: bold;"&gt;5.IP_ARP&lt;/SPAN&gt;- Bindings learned when tagged ARP packets are received on a CTS capable link&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 168.75px; font-family: Calibri; font-size: 11.0pt;"&gt;&lt;SPAN style="font-family: calibri, verdana, arial, sans-serif; color: #000000; font-size: 10pt;"&gt;&lt;SPAN style="font-weight: bold;"&gt;6.LOCAL&lt;/SPAN&gt;- Bindings of authenticated hosts which are learned via device tracking. These type of binding also includes individual hosts that are learned via ARP snooping on L2 ports. Direct switch enforcement. These fall under dynamic classification.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 168.75px; font-family: Calibri; font-size: 11.0pt;"&gt;&lt;SPAN style="font-family: calibri, verdana, arial, sans-serif; color: #000000; font-size: 10pt;"&gt;&lt;SPAN style="font-weight: bold;"&gt;7.INTERNAL&lt;/SPAN&gt;- Bindings between locally configured IP addresses and the devices own SGT. So, things like loopback addresses or addresses that are locally configured on the device can have and SGT assigned to them.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: calibri, verdana, arial, sans-serif; color: #000000; font-size: 10pt;"&gt;Now, I have found out that for Nexus NX-OS devices the priority isn't the same. This appears to be the Nexus priority.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 168.75px; font-family: Calibri; font-size: 11.0pt; color: black;"&gt;&lt;SPAN style="font-family: calibri, verdana, arial, sans-serif; color: #000000; font-size: 10pt;"&gt;&lt;SPAN style="font-weight: bold;"&gt;1.Cisco Fabric Services (CFS) -&lt;/SPAN&gt; CTS IP-SGT bindings learnt on vPC peer. This is applicable only to vPC peer devices.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 168.75px; font-family: Calibri; font-size: 11.0pt; color: black;"&gt;&lt;SPAN style="font-family: calibri, verdana, arial, sans-serif; color: #000000; font-size: 10pt;"&gt;&lt;SPAN style="font-weight: bold;"&gt;2.VLAN-SGT -&lt;/SPAN&gt; Bindings learned from snooped ARP or DHCP packets on a VLAN that is configured with a VLAN-SGT mapping.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 168.75px; font-family: Calibri; font-size: 11.0pt; color: black;"&gt;&lt;SPAN style="font-family: calibri, verdana, arial, sans-serif; color: #000000; font-size: 10pt;"&gt;&lt;SPAN style="font-weight: bold;"&gt;3&lt;/SPAN&gt;.&lt;SPAN style="font-weight: bold;"&gt;SGT-caching -&lt;/SPAN&gt; IP-SGT bindings learnt on a VLAN or VRF, where SGT-caching is configured.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 168.75px; font-family: Calibri; font-size: 11.0pt; color: black;"&gt;&lt;SPAN style="font-family: calibri, verdana, arial, sans-serif; color: #000000; font-size: 10pt;"&gt;4.&lt;SPAN style="font-weight: bold;"&gt;SXP -&lt;/SPAN&gt; Bindings learned from SXP peers.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 168.75px; font-family: Calibri; font-size: 11.0pt; color: black;"&gt;&lt;SPAN style="font-family: calibri, verdana, arial, sans-serif; color: #000000; font-size: 10pt;"&gt;&lt;SPAN style="font-weight: bold;"&gt;5.Learnt on interface -&lt;/SPAN&gt; Bindings of authenticated hosts which are learned via EPM and device tracking. This type of binding also include individual hosts that are learned via ARP snooping on L2 [I]PM configured ports.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 168.75px; font-family: Calibri; font-size: 11.0pt; color: black;"&gt;&lt;SPAN style="font-family: calibri, verdana, arial, sans-serif; color: #000000; font-size: 10pt;"&gt;&lt;SPAN style="font-weight: bold;"&gt;6.CLI -&lt;/SPAN&gt; Address bindings configured using the IP-SGT form of the cts role-based sgt-map global configuration command.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 168.75px; font-family: Calibri; font-size: 11.0pt; color: black;"&gt;&lt;SPAN style="color: #000000; font-size: 10pt; font-family: calibri, verdana, arial, sans-serif;"&gt;&lt;SPAN style="font-weight: bold;"&gt;7.Port ASIC -&lt;/SPAN&gt; SGT bindings derived inline or directly from the port, based on CTS trusted or untrusted configuration.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt;&lt;STRONG&gt;Question: Is there anyone at Cisco that can provide a listing of priorities based on platform since it appears that this is not standard across all devices participating in TrustSec?&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Mar 2019 07:41:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trustsec-sgt-binding-priority/m-p/3568368#M494089</guid>
      <dc:creator>derrick.ray1</dc:creator>
      <dc:date>2019-03-11T07:41:52Z</dc:date>
    </item>
    <item>
      <title>Re: TrustSec SGT Binding Priority</title>
      <link>https://community.cisco.com/t5/network-access-control/trustsec-sgt-binding-priority/m-p/3568369#M494106</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This has just always been the case. It's a difference between IOS and NX-OS only.&lt;/P&gt;&lt;P&gt;In fact, SGT caching is also an option for IOS and it is the 2nd highest priority:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;1. VLAN—Bindings learned from snooped ARP packets on a VLAN that has VLAN-SGT mapping configured.&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;2. CLI— Address bindings configured using the IP-SGT form of the cts role-based sgt-map global configuration command.&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;3. Layer 3 Interface—(L3IF) Bindings added due to FIB forwarding entries that have paths through one or more interfaces with consistent L3IF-SGT mapping or Identity Port Mapping on routed ports.&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;4. SXP—Bindings learned from SXP peers.&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;5. IP_ARP—Bindings learned when tagged ARP packets are received on a CTS capable link.&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;6. LOCAL—Bindings of authenticated hosts which are learned via EPM and device tracking. This type of binding also include individual hosts that are learned via ARP snooping on L2 [I]PM configured ports.&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;7. SGT CACHING — Bindings learned through the SGT Caching feature by gleaning the inline SGT in the packet.&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;8. INTERNAL—Bindings between locally configured IP addresses and the device own SGT.&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;The difference between the priorities on IOS and NX-OS have been documented in the likes of Cisco Live slides and FAQ's and is listed in the troubleshooting guide (found by searching for 'TrustSec troubleshooting guide' in search engines or more directly at: &lt;A _jive_internal="true" href="https://community.cisco.com/docs/DOC-69479#jive_content_id_Is_there_a_priority_list_when_configuring_different_classification_types_on_IOS" title="https://communities.cisco.com/docs/DOC-69479#jive_content_id_Is_there_a_priority_list_when_configuring_different_classification_types_on_IOS"&gt;https://communities.cisco.com/docs/DOC-69479#jive_content_id_Is_there_a_priority_list_when_configuring_different_classification_types_on_IOS&lt;/A&gt;)&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;I'll think of other locations where this sort of information should be posted.&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;/P&gt;&lt;P&gt;Regards, Jonothan.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 May 2017 15:57:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trustsec-sgt-binding-priority/m-p/3568369#M494106</guid>
      <dc:creator>jeaves@cisco.com</dc:creator>
      <dc:date>2017-05-04T15:57:13Z</dc:date>
    </item>
    <item>
      <title>Re: TrustSec SGT Binding Priority</title>
      <link>https://community.cisco.com/t5/network-access-control/trustsec-sgt-binding-priority/m-p/3568370#M494133</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you, Jonathan.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 May 2017 16:39:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trustsec-sgt-binding-priority/m-p/3568370#M494133</guid>
      <dc:creator>derrick.ray1</dc:creator>
      <dc:date>2017-05-04T16:39:12Z</dc:date>
    </item>
    <item>
      <title>Re: TrustSec SGT Binding Priority</title>
      <link>https://community.cisco.com/t5/network-access-control/trustsec-sgt-binding-priority/m-p/4818549#M581319</link>
      <description>&lt;P&gt;Hi Jonathan&lt;/P&gt;
&lt;P&gt;could u pls help with recognition where in that list L2-port static binding &amp;amp; RADIUS-learned SGT assignment are?&lt;/P&gt;
&lt;P&gt;thanks in advance&lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2023 14:15:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trustsec-sgt-binding-priority/m-p/4818549#M581319</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2023-04-20T14:15:19Z</dc:date>
    </item>
  </channel>
</rss>

