<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE | SXP | Nexus 7000 SGT-MAP query in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-sxp-nexus-7000-sgt-map-query/m-p/3446462#M494918</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have a customer who has a concern :&lt;/P&gt;&lt;P&gt;How do we get the static IP-SGT mappings defined in ISE to propagate to the VLAN-level on the Nexus 7K's?? This needs to be automated in a similar manner like it propagates to the default VRF on the Nexus 7K's.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background: yellow;"&gt;Troubleshooting done&lt;/SPAN&gt; :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISE is speaker and all other devices in enterprise are listeners.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Current setup, ISE push IP-SGT mappings at VRF level onto Nexus. Client is connected behind an access port VLAN due which not working properly.&lt;/P&gt;&lt;P&gt;Started troubleshooting on the N7K where traffic from AC client 10.xx.xx.29 9xx4&amp;nbsp; trying to reach 10.&lt;SPAN style="font-size: 13.3333px;"&gt;xx.xx&lt;/SPAN&gt;.7 2xxx1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Enforcement not happening correctly as &amp;lt;9xx4,&lt;SPAN style="font-size: 13.3333px;"&gt;2xxx1&lt;/SPAN&gt;&amp;gt; should deny as per SGACL matrix on ISE.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NX-DC# show logging ip access-list cache detail | i 10.&lt;SPAN style="font-size: 13.3333px;"&gt;xx.xx&lt;/SPAN&gt;.29&lt;/P&gt;&lt;P&gt;9xx4&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.xx.xx.29 10.xx.xx.243 0 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Ethernet2/xx (1)IC&lt;/P&gt;&lt;P&gt;MP (0 )OFF&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ---- -----&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Permit -----&lt;/P&gt;&lt;P&gt; ----- -----&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3&lt;/P&gt;&lt;P&gt;65519&amp;nbsp;&amp;nbsp; 10.&lt;SPAN style="font-size: 13.3333px;"&gt;xx.xx&lt;/SPAN&gt;.7 10.&lt;SPAN style="font-size: 13.3333px;"&gt;xx.xx&lt;/SPAN&gt;.29 0 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; port-channel256 (1&lt;/P&gt;&lt;P&gt;)ICMP (0 )OFF&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ---- ----- Deny&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -----&lt;/P&gt;&lt;P&gt; ----- -----&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2&lt;/P&gt;&lt;P&gt;9xx4&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.&lt;SPAN style="font-size: 13.3333px;"&gt;xx.xx&lt;/SPAN&gt;.29 10.&lt;SPAN style="font-size: 13.3333px;"&gt;xx.xx&lt;/SPAN&gt;.7 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 Ethernet2/xx (1)IC&lt;/P&gt;&lt;P&gt;MP (0 )OFF&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ---- -----&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Permit -----&lt;/P&gt;&lt;P&gt; ----- -----&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We found that sgt-map&amp;nbsp; pushed for VRF:1. However, the end client is behind access port VLAN 10.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The issue is DGT: 0, so &amp;lt;9xx4, 0&amp;gt; will get hit instead of &amp;lt;9xx4, 2xxx1&amp;gt;. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NX-DC# &lt;SPAN style="background: yellow;"&gt;sh system internal forwarding ipv4 route 10.&lt;SPAN style="font-size: 13.3333px;"&gt;xx.xx&lt;/SPAN&gt;.7 de&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;slot&amp;nbsp; 1&lt;/P&gt;&lt;P&gt;=======&lt;/P&gt;&lt;P&gt;slot&amp;nbsp; 2&lt;/P&gt;&lt;P&gt;=======&lt;/P&gt;&lt;P&gt;RPF Flags legend:&lt;/P&gt;&lt;P&gt; S - Directly attached route (S_Star)&lt;/P&gt;&lt;P&gt; V - RPF valid&lt;/P&gt;&lt;P&gt; M - SMAC IP check enabled&lt;/P&gt;&lt;P&gt; G - SGT valid&lt;/P&gt;&lt;P&gt; E - RPF External table valid&lt;/P&gt;&lt;P&gt; 10.&lt;SPAN style="font-size: 13.3333px;"&gt;xx.xx&lt;/SPAN&gt;.7/32&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ,&amp;nbsp; Vlan10&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Dev: 0 , Idx: 0xb266&amp;nbsp; , RPF Flags: VS&amp;nbsp;&amp;nbsp;&amp;nbsp; , &lt;SPAN style="background: yellow;"&gt;DGT: 0&lt;/SPAN&gt; , VPN: 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also noticed that the IP-SGT configuration for 10.&lt;SPAN style="font-size: 13.3333px;"&gt;xx.xx&lt;/SPAN&gt;.7 2xxx1 is under VRF:1, however the enforcement needs to happen on VLAN 10 so the same IP-SGT needs to be configured under VLAN 10&lt;/P&gt;&lt;P&gt;The moment I configured sgt-map for destination IP under vlan 10. Enforcement applied correctly. Traffic got denied.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE style="background: #F0C566;"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri',sans-serif;"&gt;NX-DC# sh cts role-based sgt-map | in 10.&lt;SPAN style="font-size: 13.3333px;"&gt;xx.xx&lt;/SPAN&gt;.7&lt;/SPAN&gt;&lt;/PRE&gt;&lt;PRE style="background: #F0C566;"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri',sans-serif;"&gt;10.&lt;SPAN style="font-size: 13.3333px;"&gt;xx.xx&lt;/SPAN&gt;.7&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2xxx1(BAS_CCTV_Servers)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; vlan:&lt;/SPAN&gt;&lt;/PRE&gt;&lt;PRE style="background: #F0C566;"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri',sans-serif;"&gt;10&amp;nbsp;&amp;nbsp; CLI Configured&lt;/SPAN&gt;&lt;/PRE&gt;&lt;PRE style="background: #F0C566;"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri',sans-serif;"&gt;10.&lt;SPAN style="font-size: 13.3333px;"&gt;xx.xx&lt;/SPAN&gt;.7&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2xxx1(BAS_CCTV_Servers)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; vrf:1&lt;/SPAN&gt;&lt;/PRE&gt;&lt;PRE style="background: #F0C566;"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri',sans-serif;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; CLI Configured&lt;/SPAN&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Gagan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 11 Mar 2019 08:09:48 GMT</pubDate>
    <dc:creator>Gagandeep Singh</dc:creator>
    <dc:date>2019-03-11T08:09:48Z</dc:date>
    <item>
      <title>ISE | SXP | Nexus 7000 SGT-MAP query</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-sxp-nexus-7000-sgt-map-query/m-p/3446462#M494918</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have a customer who has a concern :&lt;/P&gt;&lt;P&gt;How do we get the static IP-SGT mappings defined in ISE to propagate to the VLAN-level on the Nexus 7K's?? This needs to be automated in a similar manner like it propagates to the default VRF on the Nexus 7K's.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background: yellow;"&gt;Troubleshooting done&lt;/SPAN&gt; :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISE is speaker and all other devices in enterprise are listeners.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Current setup, ISE push IP-SGT mappings at VRF level onto Nexus. Client is connected behind an access port VLAN due which not working properly.&lt;/P&gt;&lt;P&gt;Started troubleshooting on the N7K where traffic from AC client 10.xx.xx.29 9xx4&amp;nbsp; trying to reach 10.&lt;SPAN style="font-size: 13.3333px;"&gt;xx.xx&lt;/SPAN&gt;.7 2xxx1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Enforcement not happening correctly as &amp;lt;9xx4,&lt;SPAN style="font-size: 13.3333px;"&gt;2xxx1&lt;/SPAN&gt;&amp;gt; should deny as per SGACL matrix on ISE.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NX-DC# show logging ip access-list cache detail | i 10.&lt;SPAN style="font-size: 13.3333px;"&gt;xx.xx&lt;/SPAN&gt;.29&lt;/P&gt;&lt;P&gt;9xx4&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.xx.xx.29 10.xx.xx.243 0 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Ethernet2/xx (1)IC&lt;/P&gt;&lt;P&gt;MP (0 )OFF&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ---- -----&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Permit -----&lt;/P&gt;&lt;P&gt; ----- -----&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3&lt;/P&gt;&lt;P&gt;65519&amp;nbsp;&amp;nbsp; 10.&lt;SPAN style="font-size: 13.3333px;"&gt;xx.xx&lt;/SPAN&gt;.7 10.&lt;SPAN style="font-size: 13.3333px;"&gt;xx.xx&lt;/SPAN&gt;.29 0 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; port-channel256 (1&lt;/P&gt;&lt;P&gt;)ICMP (0 )OFF&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ---- ----- Deny&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -----&lt;/P&gt;&lt;P&gt; ----- -----&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2&lt;/P&gt;&lt;P&gt;9xx4&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.&lt;SPAN style="font-size: 13.3333px;"&gt;xx.xx&lt;/SPAN&gt;.29 10.&lt;SPAN style="font-size: 13.3333px;"&gt;xx.xx&lt;/SPAN&gt;.7 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 Ethernet2/xx (1)IC&lt;/P&gt;&lt;P&gt;MP (0 )OFF&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ---- -----&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Permit -----&lt;/P&gt;&lt;P&gt; ----- -----&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We found that sgt-map&amp;nbsp; pushed for VRF:1. However, the end client is behind access port VLAN 10.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The issue is DGT: 0, so &amp;lt;9xx4, 0&amp;gt; will get hit instead of &amp;lt;9xx4, 2xxx1&amp;gt;. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NX-DC# &lt;SPAN style="background: yellow;"&gt;sh system internal forwarding ipv4 route 10.&lt;SPAN style="font-size: 13.3333px;"&gt;xx.xx&lt;/SPAN&gt;.7 de&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;slot&amp;nbsp; 1&lt;/P&gt;&lt;P&gt;=======&lt;/P&gt;&lt;P&gt;slot&amp;nbsp; 2&lt;/P&gt;&lt;P&gt;=======&lt;/P&gt;&lt;P&gt;RPF Flags legend:&lt;/P&gt;&lt;P&gt; S - Directly attached route (S_Star)&lt;/P&gt;&lt;P&gt; V - RPF valid&lt;/P&gt;&lt;P&gt; M - SMAC IP check enabled&lt;/P&gt;&lt;P&gt; G - SGT valid&lt;/P&gt;&lt;P&gt; E - RPF External table valid&lt;/P&gt;&lt;P&gt; 10.&lt;SPAN style="font-size: 13.3333px;"&gt;xx.xx&lt;/SPAN&gt;.7/32&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ,&amp;nbsp; Vlan10&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Dev: 0 , Idx: 0xb266&amp;nbsp; , RPF Flags: VS&amp;nbsp;&amp;nbsp;&amp;nbsp; , &lt;SPAN style="background: yellow;"&gt;DGT: 0&lt;/SPAN&gt; , VPN: 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also noticed that the IP-SGT configuration for 10.&lt;SPAN style="font-size: 13.3333px;"&gt;xx.xx&lt;/SPAN&gt;.7 2xxx1 is under VRF:1, however the enforcement needs to happen on VLAN 10 so the same IP-SGT needs to be configured under VLAN 10&lt;/P&gt;&lt;P&gt;The moment I configured sgt-map for destination IP under vlan 10. Enforcement applied correctly. Traffic got denied.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE style="background: #F0C566;"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri',sans-serif;"&gt;NX-DC# sh cts role-based sgt-map | in 10.&lt;SPAN style="font-size: 13.3333px;"&gt;xx.xx&lt;/SPAN&gt;.7&lt;/SPAN&gt;&lt;/PRE&gt;&lt;PRE style="background: #F0C566;"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri',sans-serif;"&gt;10.&lt;SPAN style="font-size: 13.3333px;"&gt;xx.xx&lt;/SPAN&gt;.7&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2xxx1(BAS_CCTV_Servers)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; vlan:&lt;/SPAN&gt;&lt;/PRE&gt;&lt;PRE style="background: #F0C566;"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri',sans-serif;"&gt;10&amp;nbsp;&amp;nbsp; CLI Configured&lt;/SPAN&gt;&lt;/PRE&gt;&lt;PRE style="background: #F0C566;"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri',sans-serif;"&gt;10.&lt;SPAN style="font-size: 13.3333px;"&gt;xx.xx&lt;/SPAN&gt;.7&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2xxx1(BAS_CCTV_Servers)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; vrf:1&lt;/SPAN&gt;&lt;/PRE&gt;&lt;PRE style="background: #F0C566;"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri',sans-serif;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; CLI Configured&lt;/SPAN&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Gagan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Mar 2019 08:09:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-sxp-nexus-7000-sgt-map-query/m-p/3446462#M494918</guid>
      <dc:creator>Gagandeep Singh</dc:creator>
      <dc:date>2019-03-11T08:09:48Z</dc:date>
    </item>
    <item>
      <title>Re: ISE | SXP | Nexus 7000 SGT-MAP query</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-sxp-nexus-7000-sgt-map-query/m-p/3446463#M494940</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Moving to &lt;A _jive_internal="true" href="https://community.cisco.com/community/technology/security/pa/trustsec"&gt; TrustSec&lt;/A&gt; space.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Nov 2017 02:14:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-sxp-nexus-7000-sgt-map-query/m-p/3446463#M494940</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-11-15T02:14:00Z</dc:date>
    </item>
    <item>
      <title>Re: ISE | SXP | Nexus 7000 SGT-MAP query</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-sxp-nexus-7000-sgt-map-query/m-p/3446464#M494955</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The IP-SGT mapping propagated from ISE to the N7K vrf should bind, as long as the N7K isn't learning a conflicging mapping from a higher priority source. As long as the device has the correct IP-SGT mapping, the egress policies associated with those mappings should apply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From your problem description, I believe you're saying 10.x.x.29 should have SGT-9xx4 and 10.x.x.7 should have SGT-2xxx1 and the egress policy should deny it, but it does not appear to enforce correctly until you manually add a VLAN mapping on the N7K?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;While the problem is occurring, have you verified that the enforcement device has the correct IP-SGT mappings for the source and destination? Can you provide output from "&lt;STRONG&gt;sh cts ro sgt-m | i 10.x.x.7&lt;/STRONG&gt;" and "&lt;STRONG&gt;sh cts ro sgt-m | i 10.x.x.29&lt;/STRONG&gt;" from the enforcement device?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, can you verify that egress policy is correct in &lt;STRONG&gt;both&lt;/STRONG&gt; directions on the enforcement device? Please provide output from the N7K of the following two commands: "&lt;STRONG&gt;sh cts ro poli from 9xx4 to 2xxx1&lt;/STRONG&gt;" and "&lt;STRONG&gt;sh cts ro poli from 2xxx1 to 9xx4&lt;/STRONG&gt;".&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Nov 2017 22:09:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-sxp-nexus-7000-sgt-map-query/m-p/3446464#M494955</guid>
      <dc:creator>Config T</dc:creator>
      <dc:date>2017-11-28T22:09:11Z</dc:date>
    </item>
  </channel>
</rss>

