<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TrustSec IP-SGT Binding Limitation in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/trustsec-ip-sgt-binding-limitation/m-p/3701826#M507821</link>
    <description>&lt;P&gt;Hi TJ,&lt;BR /&gt;In cat4K, the DGT derivation limit of 2000 entries applies to only ‘switched traffic’ as it uses 1 block of Input ACL (2K entries) for deriving DGT in case of switched traffic.&lt;BR /&gt;For L3 traffic, we use FIB to derive DGT and hence this limit doesn’t apply.&lt;BR /&gt;The limit is applicable to all Sup7, 8 and 9 Supervisors.&lt;/P&gt;</description>
    <pubDate>Thu, 06 Sep 2018 08:41:58 GMT</pubDate>
    <dc:creator>jeaves@cisco.com</dc:creator>
    <dc:date>2018-09-06T08:41:58Z</dc:date>
    <item>
      <title>TrustSec IP-SGT Binding Limitation</title>
      <link>https://community.cisco.com/t5/network-access-control/trustsec-ip-sgt-binding-limitation/m-p/3700970#M507813</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;As per the below table, there are limits on IP-SGT bindings for relevant switches. What i want to know is, how are the L2 and L3 limits calculated? What parameters does the TrustSec feature check in the 4500 series switch to build up this limit?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IP-SGT Binding Limits.JPG" style="width: 550px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/18145i5BC9E9671274AD3A/image-dimensions/550x330?v=v2" width="550" height="330" role="button" title="IP-SGT Binding Limits.JPG" alt="IP-SGT Binding Limits.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;TJ&lt;/P&gt;</description>
      <pubDate>Wed, 05 Sep 2018 07:07:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trustsec-ip-sgt-binding-limitation/m-p/3700970#M507813</guid>
      <dc:creator>firefox</dc:creator>
      <dc:date>2018-09-05T07:07:06Z</dc:date>
    </item>
    <item>
      <title>Re: TrustSec IP-SGT Binding Limitation</title>
      <link>https://community.cisco.com/t5/network-access-control/trustsec-ip-sgt-binding-limitation/m-p/3701215#M507815</link>
      <description>&lt;P&gt;As far as I remember the mappings are stored in ASICs in the switches.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Sep 2018 14:15:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trustsec-ip-sgt-binding-limitation/m-p/3701215#M507815</guid>
      <dc:creator>umahar</dc:creator>
      <dc:date>2018-09-05T14:15:36Z</dc:date>
    </item>
    <item>
      <title>Re: TrustSec IP-SGT Binding Limitation</title>
      <link>https://community.cisco.com/t5/network-access-control/trustsec-ip-sgt-binding-limitation/m-p/3701269#M507817</link>
      <description>&lt;P&gt;Thanks unmahar, but my query is specific to how the switch classifies the IP-SGT binding as L2 or L3? Is it because of the way the switch has learned the IP details, or is it because of routes, vlans etc?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Sep 2018 15:02:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trustsec-ip-sgt-binding-limitation/m-p/3701269#M507817</guid>
      <dc:creator>firefox</dc:creator>
      <dc:date>2018-09-05T15:02:54Z</dc:date>
    </item>
    <item>
      <title>Re: TrustSec IP-SGT Binding Limitation</title>
      <link>https://community.cisco.com/t5/network-access-control/trustsec-ip-sgt-binding-limitation/m-p/3701299#M507818</link>
      <description>&lt;P&gt;The way switches derive source SGTs and destination SGTs is different for L2 switched traffic and L3 routed traffic. L3 has scale than L2 and hence different values.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Sep 2018 15:34:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trustsec-ip-sgt-binding-limitation/m-p/3701299#M507818</guid>
      <dc:creator>umahar</dc:creator>
      <dc:date>2018-09-05T15:34:08Z</dc:date>
    </item>
    <item>
      <title>Re: TrustSec IP-SGT Binding Limitation</title>
      <link>https://community.cisco.com/t5/network-access-control/trustsec-ip-sgt-binding-limitation/m-p/3701351#M507819</link>
      <description>&lt;P&gt;HI umahar, is there a document that you can point me to, which shows how switches derive source SGTs and destination SGTs ?&lt;/P&gt;</description>
      <pubDate>Wed, 05 Sep 2018 16:21:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trustsec-ip-sgt-binding-limitation/m-p/3701351#M507819</guid>
      <dc:creator>firefox</dc:creator>
      <dc:date>2018-09-05T16:21:45Z</dc:date>
    </item>
    <item>
      <title>Re: TrustSec IP-SGT Binding Limitation</title>
      <link>https://community.cisco.com/t5/network-access-control/trustsec-ip-sgt-binding-limitation/m-p/3701599#M507820</link>
      <description>&lt;P&gt;Please see attached.&amp;nbsp; They are taken from the "Advanced Security Group Tags: The Detailed Walk Through - BRKSEC-3690" session at Cisco Live.&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Sep 2018 22:10:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trustsec-ip-sgt-binding-limitation/m-p/3701599#M507820</guid>
      <dc:creator>faylee</dc:creator>
      <dc:date>2018-09-05T22:10:31Z</dc:date>
    </item>
    <item>
      <title>Re: TrustSec IP-SGT Binding Limitation</title>
      <link>https://community.cisco.com/t5/network-access-control/trustsec-ip-sgt-binding-limitation/m-p/3701826#M507821</link>
      <description>&lt;P&gt;Hi TJ,&lt;BR /&gt;In cat4K, the DGT derivation limit of 2000 entries applies to only ‘switched traffic’ as it uses 1 block of Input ACL (2K entries) for deriving DGT in case of switched traffic.&lt;BR /&gt;For L3 traffic, we use FIB to derive DGT and hence this limit doesn’t apply.&lt;BR /&gt;The limit is applicable to all Sup7, 8 and 9 Supervisors.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Sep 2018 08:41:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trustsec-ip-sgt-binding-limitation/m-p/3701826#M507821</guid>
      <dc:creator>jeaves@cisco.com</dc:creator>
      <dc:date>2018-09-06T08:41:58Z</dc:date>
    </item>
  </channel>
</rss>

