<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Pushing IP-SGT mappings to Cisco switch in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/pushing-ip-sgt-mappings-to-cisco-switch/m-p/3580055#M525200</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d; font-family: 'Calibri','sans-serif'; font-size: 11pt;"&gt;Thank you for the suggestion given previously.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d; font-family: 'Calibri','sans-serif'; font-size: 11pt;"&gt;By following the below suggestion, given to add device&amp;nbsp; steps I am able to&amp;nbsp; find the device in ISE and tried deploying the IP-SGT binding. It got deployed to the device globally. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d; font-family: 'Calibri','sans-serif'; font-size: 11pt;"&gt;However my requirement is that, the binding should get deployed to the device for a VRF “sgt”. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d; font-family: 'Calibri','sans-serif'; font-size: 11pt;"&gt;In device I have configured VRF “sgt” . In ISE side I have configured the below.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt;&lt;IMG __jive_id="106777" alt="Screen capture" class="image-1 jive-image" height="69" src="https://community.cisco.com/legacyfs/online/fusion/106777_pastedImage_0.png" style="width: 620px; height: 36px;" width="1173" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d; font-family: 'Calibri','sans-serif'; font-size: 11pt;"&gt;In ISE I have given deployed via as a “sgt” but still it is coming globally. Any suggestion to make it deployed to vrf “sgt”.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt; &lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt; &lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt; &lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;TABLE border="0" cellpadding="0" cellspacing="0" style="background: white;" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD style="padding: 7.5pt 0px 15pt; border: #000000; border-image: none;"&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt; &lt;/SPAN&gt;&lt;H2&gt;&lt;SPAN style="color: #666666; font-size: 18pt; font-family: 'Helvetica','sans-serif'; font-weight: normal; mso-fareast-font-family: 'Times New Roman';"&gt;Hi &lt;/SPAN&gt;&lt;/H2&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt; &lt;/SPAN&gt;&lt;DIV style="margin-bottom: 15pt;"&gt;&lt;SPAN style="color: #999999; font-family: 'Helvetica','sans-serif'; font-size: 9pt;"&gt;reply from &lt;A _jive_internal="true" href="https://community.cisco.com/people/harips"&gt;&lt;SPAN style="color: #3778c7; text-decoration: underline;"&gt;Hariprasad Holla&lt;/SPAN&gt;&lt;/A&gt; in &lt;EM&gt;Technology &amp;gt; Security Community &amp;gt; Policy and Access &amp;gt; Identity Services Engine (ISE)&lt;/EM&gt; - &lt;A _jive_internal="true" href="https://community.cisco.com/message/252925#252925"&gt;&lt;SPAN style="color: #3778c7; text-decoration: underline;"&gt;View the full discussion&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt; &lt;/SPAN&gt;&lt;DIV align="center" style="text-align: center;"&gt; &lt;/DIV&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Times New Roman;"&gt; &lt;/SPAN&gt;&lt;DIV&gt;&lt;SPAN style="color: #666666; font-family: 'Helvetica','sans-serif'; font-size: 10.5pt;"&gt;The IP-SGT bindings from ISE can be pushed to the network via 2 methods:&lt;/SPAN&gt;&lt;/DIV&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Times New Roman;"&gt; &lt;/SPAN&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Times New Roman;"&gt; &lt;/SPAN&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Times New Roman;"&gt; &lt;/SPAN&gt;&lt;DIV&gt;&lt;SPAN style="color: #666666; font-family: 'Helvetica','sans-serif'; font-size: 10.5pt;"&gt;1) CLI configuration &lt;/SPAN&gt;&lt;/DIV&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Times New Roman;"&gt; &lt;/SPAN&gt;&lt;DIV&gt;&lt;SPAN style="color: #666666; font-family: 'Helvetica','sans-serif'; font-size: 10.5pt;"&gt;2) ISE SXP&lt;/SPAN&gt;&lt;/DIV&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Times New Roman;"&gt; &lt;/SPAN&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Times New Roman;"&gt; &lt;/SPAN&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Times New Roman;"&gt; &lt;/SPAN&gt;&lt;DIV&gt;&lt;SPAN style="color: #666666; font-family: 'Helvetica','sans-serif'; font-size: 10.5pt;"&gt;You seem to be using method-1, which requires you to define the network device’s SSH login credentials so that ISE can configure it for static IP-to-SGT bindings.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Times New Roman;"&gt; &lt;/SPAN&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Times New Roman;"&gt; &lt;/SPAN&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Times New Roman;"&gt; &lt;/SPAN&gt;&lt;DIV&gt;&lt;SPAN style="color: #666666; font-family: 'Helvetica','sans-serif'; font-size: 10.5pt;"&gt;Here’s how you do it:&lt;/SPAN&gt;&lt;/DIV&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Times New Roman;"&gt; &lt;/SPAN&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Times New Roman;"&gt; &lt;/SPAN&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Times New Roman;"&gt; &lt;/SPAN&gt;&lt;DIV&gt;&lt;SPAN style="color: #666666; font-family: 'Helvetica','sans-serif'; font-size: 10.5pt;"&gt;Under ‘Advanced TrustSec Settings’ within the Network Device configuration in ISE, specify the SSH login details:&lt;/SPAN&gt;&lt;/DIV&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Times New Roman;"&gt; &lt;/SPAN&gt;&lt;DIV&gt;&lt;SPAN style="color: #666666; font-family: 'Helvetica','sans-serif'; font-size: 10.5pt;"&gt;&lt;A _jive_internal="true" href="https://community.cisco.com/servlet/JiveServlet/downloadImage/2-252925-106739/Screen Shot 2017-04-26 at 9.44.33 AM.png"&gt;&lt;SPAN style="color: #3778c7; text-decoration: underline;"&gt;https://communities.cisco.com/servlet/JiveServlet/downloadImage/2-252925-106739/385-190/Screen+Shot+2017-04-26+at+9.44.33+AM.png &lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Times New Roman;"&gt; &lt;/SPAN&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Times New Roman;"&gt; &lt;/SPAN&gt;&lt;DIV&gt;&lt;SPAN style="color: #666666; font-family: 'Helvetica','sans-serif'; font-size: 10.5pt;"&gt;Then under TrustSec Work center &amp;gt; Components, you should be able to see this network device to push the static IP-to-SGT binding.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Times New Roman;"&gt; &lt;/SPAN&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Times New Roman;"&gt; &lt;/SPAN&gt;&lt;DIV&gt;&lt;SPAN style="color: #666666; font-family: 'Helvetica','sans-serif'; font-size: 10.5pt;"&gt;&lt;A _jive_internal="true" href="https://community.cisco.com/servlet/JiveServlet/downloadImage/2-252925-106740/Screen Shot 2017-04-26 at 9.45.08 AM.png"&gt;&lt;SPAN style="color: #3778c7; text-decoration: underline;"&gt;https://communities.cisco.com/servlet/JiveServlet/downloadImage/2-252925-106740/1245-900/Screen+Shot+2017-04-26+at+9.45.08+AM.png &lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;SPAN style="color: #000000; font-size: 12pt;"&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt; &lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt; &lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt; &lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt; &lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt; &lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt; &lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt; &lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;TABLE border="0" cellpadding="0" cellspacing="0" style="background: whitesmoke;" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD style="padding: 7.5pt; border: #000000; border-image: none;" valign="top"&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt; &lt;/SPAN&gt;&lt;DIV style="margin: 30pt 0px 0px;"&gt;&lt;SPAN style="color: #666666; font-family: 'Helvetica','sans-serif'; font-size: 10.5pt;"&gt;Reply to this message by replying to this email, or &lt;A _jive_internal="true" href="https://community.cisco.com/message/252925#252925"&gt;&lt;SPAN style="color: #3778c7; text-decoration: underline;"&gt;go to the message on Cisco Communities&lt;/SPAN&gt;&lt;/A&gt; &lt;/SPAN&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD style="padding: 7.5pt; border: #000000; border-image: none;" valign="top"&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt; &lt;/SPAN&gt;&lt;DIV style="margin: 30pt 0px 0px;"&gt;&lt;SPAN style="color: #666666; font-family: 'Helvetica','sans-serif'; font-size: 10.5pt;"&gt;Start a new discussion in Technology &amp;gt; Security Community &amp;gt; Policy and Access &amp;gt; Identity Services Engine (ISE) by &lt;A href="mailto:discussions-community-technology-security-pa-ise@cisco-marketing.hosted.jivesoftware.com"&gt;&lt;SPAN style="color: #3778c7; text-decoration: underline;"&gt;email&lt;/SPAN&gt;&lt;/A&gt; or at &lt;A _jive_internal="true" href="https://community.cisco.com/choose-container.jspa?contentType=1&amp;amp;containerType=14&amp;amp;container=5301"&gt;&lt;SPAN style="color: #3778c7; text-decoration: underline;"&gt;Cisco Communities&lt;/SPAN&gt;&lt;/A&gt; &lt;/SPAN&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 27 Apr 2017 12:31:02 GMT</pubDate>
    <dc:creator>snatara2</dc:creator>
    <dc:date>2017-04-27T12:31:02Z</dc:date>
    <item>
      <title>Pushing IP-SGT mappings to Cisco switch</title>
      <link>https://community.cisco.com/t5/network-access-control/pushing-ip-sgt-mappings-to-cisco-switch/m-p/3580055#M525200</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d; font-family: 'Calibri','sans-serif'; font-size: 11pt;"&gt;Thank you for the suggestion given previously.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d; font-family: 'Calibri','sans-serif'; font-size: 11pt;"&gt;By following the below suggestion, given to add device&amp;nbsp; steps I am able to&amp;nbsp; find the device in ISE and tried deploying the IP-SGT binding. It got deployed to the device globally. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d; font-family: 'Calibri','sans-serif'; font-size: 11pt;"&gt;However my requirement is that, the binding should get deployed to the device for a VRF “sgt”. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d; font-family: 'Calibri','sans-serif'; font-size: 11pt;"&gt;In device I have configured VRF “sgt” . In ISE side I have configured the below.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt;&lt;IMG __jive_id="106777" alt="Screen capture" class="image-1 jive-image" height="69" src="https://community.cisco.com/legacyfs/online/fusion/106777_pastedImage_0.png" style="width: 620px; height: 36px;" width="1173" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d; font-family: 'Calibri','sans-serif'; font-size: 11pt;"&gt;In ISE I have given deployed via as a “sgt” but still it is coming globally. Any suggestion to make it deployed to vrf “sgt”.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt; &lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt; &lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt; &lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;TABLE border="0" cellpadding="0" cellspacing="0" style="background: white;" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD style="padding: 7.5pt 0px 15pt; border: #000000; border-image: none;"&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt; &lt;/SPAN&gt;&lt;H2&gt;&lt;SPAN style="color: #666666; font-size: 18pt; font-family: 'Helvetica','sans-serif'; font-weight: normal; mso-fareast-font-family: 'Times New Roman';"&gt;Hi &lt;/SPAN&gt;&lt;/H2&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt; &lt;/SPAN&gt;&lt;DIV style="margin-bottom: 15pt;"&gt;&lt;SPAN style="color: #999999; font-family: 'Helvetica','sans-serif'; font-size: 9pt;"&gt;reply from &lt;A _jive_internal="true" href="https://community.cisco.com/people/harips"&gt;&lt;SPAN style="color: #3778c7; text-decoration: underline;"&gt;Hariprasad Holla&lt;/SPAN&gt;&lt;/A&gt; in &lt;EM&gt;Technology &amp;gt; Security Community &amp;gt; Policy and Access &amp;gt; Identity Services Engine (ISE)&lt;/EM&gt; - &lt;A _jive_internal="true" href="https://community.cisco.com/message/252925#252925"&gt;&lt;SPAN style="color: #3778c7; text-decoration: underline;"&gt;View the full discussion&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt; &lt;/SPAN&gt;&lt;DIV align="center" style="text-align: center;"&gt; &lt;/DIV&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Times New Roman;"&gt; &lt;/SPAN&gt;&lt;DIV&gt;&lt;SPAN style="color: #666666; font-family: 'Helvetica','sans-serif'; font-size: 10.5pt;"&gt;The IP-SGT bindings from ISE can be pushed to the network via 2 methods:&lt;/SPAN&gt;&lt;/DIV&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Times New Roman;"&gt; &lt;/SPAN&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Times New Roman;"&gt; &lt;/SPAN&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Times New Roman;"&gt; &lt;/SPAN&gt;&lt;DIV&gt;&lt;SPAN style="color: #666666; font-family: 'Helvetica','sans-serif'; font-size: 10.5pt;"&gt;1) CLI configuration &lt;/SPAN&gt;&lt;/DIV&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Times New Roman;"&gt; &lt;/SPAN&gt;&lt;DIV&gt;&lt;SPAN style="color: #666666; font-family: 'Helvetica','sans-serif'; font-size: 10.5pt;"&gt;2) ISE SXP&lt;/SPAN&gt;&lt;/DIV&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Times New Roman;"&gt; &lt;/SPAN&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Times New Roman;"&gt; &lt;/SPAN&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Times New Roman;"&gt; &lt;/SPAN&gt;&lt;DIV&gt;&lt;SPAN style="color: #666666; font-family: 'Helvetica','sans-serif'; font-size: 10.5pt;"&gt;You seem to be using method-1, which requires you to define the network device’s SSH login credentials so that ISE can configure it for static IP-to-SGT bindings.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Times New Roman;"&gt; &lt;/SPAN&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Times New Roman;"&gt; &lt;/SPAN&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Times New Roman;"&gt; &lt;/SPAN&gt;&lt;DIV&gt;&lt;SPAN style="color: #666666; font-family: 'Helvetica','sans-serif'; font-size: 10.5pt;"&gt;Here’s how you do it:&lt;/SPAN&gt;&lt;/DIV&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Times New Roman;"&gt; &lt;/SPAN&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Times New Roman;"&gt; &lt;/SPAN&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Times New Roman;"&gt; &lt;/SPAN&gt;&lt;DIV&gt;&lt;SPAN style="color: #666666; font-family: 'Helvetica','sans-serif'; font-size: 10.5pt;"&gt;Under ‘Advanced TrustSec Settings’ within the Network Device configuration in ISE, specify the SSH login details:&lt;/SPAN&gt;&lt;/DIV&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Times New Roman;"&gt; &lt;/SPAN&gt;&lt;DIV&gt;&lt;SPAN style="color: #666666; font-family: 'Helvetica','sans-serif'; font-size: 10.5pt;"&gt;&lt;A _jive_internal="true" href="https://community.cisco.com/servlet/JiveServlet/downloadImage/2-252925-106739/Screen Shot 2017-04-26 at 9.44.33 AM.png"&gt;&lt;SPAN style="color: #3778c7; text-decoration: underline;"&gt;https://communities.cisco.com/servlet/JiveServlet/downloadImage/2-252925-106739/385-190/Screen+Shot+2017-04-26+at+9.44.33+AM.png &lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Times New Roman;"&gt; &lt;/SPAN&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Times New Roman;"&gt; &lt;/SPAN&gt;&lt;DIV&gt;&lt;SPAN style="color: #666666; font-family: 'Helvetica','sans-serif'; font-size: 10.5pt;"&gt;Then under TrustSec Work center &amp;gt; Components, you should be able to see this network device to push the static IP-to-SGT binding.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Times New Roman;"&gt; &lt;/SPAN&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Times New Roman;"&gt; &lt;/SPAN&gt;&lt;DIV&gt;&lt;SPAN style="color: #666666; font-family: 'Helvetica','sans-serif'; font-size: 10.5pt;"&gt;&lt;A _jive_internal="true" href="https://community.cisco.com/servlet/JiveServlet/downloadImage/2-252925-106740/Screen Shot 2017-04-26 at 9.45.08 AM.png"&gt;&lt;SPAN style="color: #3778c7; text-decoration: underline;"&gt;https://communities.cisco.com/servlet/JiveServlet/downloadImage/2-252925-106740/1245-900/Screen+Shot+2017-04-26+at+9.45.08+AM.png &lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;SPAN style="color: #000000; font-size: 12pt;"&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt; &lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt; &lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt; &lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt; &lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt; &lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt; &lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt; &lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;TABLE border="0" cellpadding="0" cellspacing="0" style="background: whitesmoke;" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD style="padding: 7.5pt; border: #000000; border-image: none;" valign="top"&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt; &lt;/SPAN&gt;&lt;DIV style="margin: 30pt 0px 0px;"&gt;&lt;SPAN style="color: #666666; font-family: 'Helvetica','sans-serif'; font-size: 10.5pt;"&gt;Reply to this message by replying to this email, or &lt;A _jive_internal="true" href="https://community.cisco.com/message/252925#252925"&gt;&lt;SPAN style="color: #3778c7; text-decoration: underline;"&gt;go to the message on Cisco Communities&lt;/SPAN&gt;&lt;/A&gt; &lt;/SPAN&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD style="padding: 7.5pt; border: #000000; border-image: none;" valign="top"&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt; &lt;/SPAN&gt;&lt;DIV style="margin: 30pt 0px 0px;"&gt;&lt;SPAN style="color: #666666; font-family: 'Helvetica','sans-serif'; font-size: 10.5pt;"&gt;Start a new discussion in Technology &amp;gt; Security Community &amp;gt; Policy and Access &amp;gt; Identity Services Engine (ISE) by &lt;A href="mailto:discussions-community-technology-security-pa-ise@cisco-marketing.hosted.jivesoftware.com"&gt;&lt;SPAN style="color: #3778c7; text-decoration: underline;"&gt;email&lt;/SPAN&gt;&lt;/A&gt; or at &lt;A _jive_internal="true" href="https://community.cisco.com/choose-container.jspa?contentType=1&amp;amp;containerType=14&amp;amp;container=5301"&gt;&lt;SPAN style="color: #3778c7; text-decoration: underline;"&gt;Cisco Communities&lt;/SPAN&gt;&lt;/A&gt; &lt;/SPAN&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Apr 2017 12:31:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pushing-ip-sgt-mappings-to-cisco-switch/m-p/3580055#M525200</guid>
      <dc:creator>snatara2</dc:creator>
      <dc:date>2017-04-27T12:31:02Z</dc:date>
    </item>
    <item>
      <title>Re: Hi Team</title>
      <link>https://community.cisco.com/t5/network-access-control/pushing-ip-sgt-mappings-to-cisco-switch/m-p/3580056#M525201</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Srinivasan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The 'SGT Mapping groups' on ISE is not same as the VRFs within the network. I believe, the IP-to-SGT mapping from ISE is pushed down to the network for the IPs available on the global route table. &lt;A href="https://community.cisco.com//u1/311675"&gt;kthumula&lt;/A&gt;, Could you confirm ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers!&lt;/P&gt;&lt;P&gt;-Hari&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Apr 2017 06:21:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pushing-ip-sgt-mappings-to-cisco-switch/m-p/3580056#M525201</guid>
      <dc:creator>hariholla</dc:creator>
      <dc:date>2017-04-28T06:21:31Z</dc:date>
    </item>
    <item>
      <title>Re: Hi Team</title>
      <link>https://community.cisco.com/t5/network-access-control/pushing-ip-sgt-mappings-to-cisco-switch/m-p/3580057#M525202</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Hari,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have 10.10.10.2 under VRF “sgt”,  in routing table. And I have created the IP-SGT binding in ISE and deploying it to device still it is coming to globally. Please find the details below.&lt;/P&gt;&lt;P&gt;Sup6t-snv#sh run int t3/3&lt;/P&gt;&lt;P&gt;Building configuration...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Current configuration : 96 bytes&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface TenGigabitEthernet3/3&lt;/P&gt;&lt;P&gt;vrf forwarding sgt&lt;/P&gt;&lt;P&gt;ip address 10.10.10.2 255.255.255.0&lt;/P&gt;&lt;P&gt;end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sup6t-snv#sh ip route vrf sgt&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Routing Table: sgt&lt;/P&gt;&lt;P&gt;Codes: L - local, C - connected, S - static, R - RIP, M - mobile, B - BGP&lt;/P&gt;&lt;P&gt;       D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area&lt;/P&gt;&lt;P&gt;       N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2&lt;/P&gt;&lt;P&gt;       E1 - OSPF external type 1, E2 - OSPF external type 2&lt;/P&gt;&lt;P&gt;       i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2&lt;/P&gt;&lt;P&gt;       ia - IS-IS inter area, * - candidate default, U - per-user static route&lt;/P&gt;&lt;P&gt;       o - ODR, P - periodic downloaded static route, H - NHRP, l - LISP&lt;/P&gt;&lt;P&gt;       a - application route&lt;/P&gt;&lt;P&gt;       + - replicated route, % - next hop override, p - overrides from PfR&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gateway of last resort is not set&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;      10.0.0.0/8 is variably subnetted, 2 subnets, 2 masks&lt;/P&gt;&lt;P&gt;C        10.10.10.0/24 is directly connected, TenGigabitEthernet3/3&lt;/P&gt;&lt;P&gt;L        10.10.10.2/32 is directly connected, TenGigabitEthernet3/3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sup6t-snv#sh cts role-based sgt-map all&lt;/P&gt;&lt;P&gt;Active IPv4-SGT Bindings Information&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IP Address              SGT     Source&lt;/P&gt;&lt;P&gt;============================================&lt;/P&gt;&lt;P&gt;10.10.10.2              5       CLI&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IP-SGT Active Bindings Summary&lt;/P&gt;&lt;P&gt;============================================&lt;/P&gt;&lt;P&gt;Total number of CLI      bindings = 1&lt;/P&gt;&lt;P&gt;Total number of active   bindings = 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However the SGT downloaded for the device is getting added for this IP under VRF.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sup6t-snv#sh cts role-based sgt-map vrf sgt all&lt;/P&gt;&lt;P&gt;%IPv6 protocol is not enabled in VRF sgt&lt;/P&gt;&lt;P&gt;Active IPv4-SGT Bindings Information&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IP Address              SGT     Source&lt;/P&gt;&lt;P&gt;============================================&lt;/P&gt;&lt;P&gt;10.10.10.2              8       INTERNAL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IP-SGT Active Bindings Summary&lt;/P&gt;&lt;P&gt;============================================&lt;/P&gt;&lt;P&gt;Total number of INTERNAL bindings = 1&lt;/P&gt;&lt;P&gt;Total number of active   bindings = 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have given “sgt” as Deploy via and it has been created as an SXP Domain. Do we need to do anything related to that in ISE?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Srinivasan.N&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Apr 2017 08:25:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pushing-ip-sgt-mappings-to-cisco-switch/m-p/3580057#M525202</guid>
      <dc:creator>snatara2</dc:creator>
      <dc:date>2017-04-28T08:25:16Z</dc:date>
    </item>
    <item>
      <title>Re: Hi Team</title>
      <link>https://community.cisco.com/t5/network-access-control/pushing-ip-sgt-mappings-to-cisco-switch/m-p/3580058#M525203</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The mappings pushed from ISE would be deployed to the global. To have VRF-aware SGT, ISE (radius config) need to be part of that VRF.&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_usr_cts/configuration/15-sy/sec-cts-15-sy-book/sec-cts-vrf-sgt.pdf" title="http://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_usr_cts/configuration/15-sy/sec-cts-15-sy-book/sec-cts-vrf-sgt.pdf"&gt;http://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_usr_cts/configuration/15-sy/sec-cts-15-sy-book/sec-cts-vrf-sgt.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;An SXP Domain in ISE provides a means to logically group network devices to which SXP mappings should be exchanged. These “Domains” are optional and if none are defined the system default domain named “default” is used. This allows for granular control of where specific SXP mappings will be advertised. Similar to the one (sgt) which you created above in ISE.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Apr 2017 14:01:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pushing-ip-sgt-mappings-to-cisco-switch/m-p/3580058#M525203</guid>
      <dc:creator>kthumula</dc:creator>
      <dc:date>2017-04-28T14:01:22Z</dc:date>
    </item>
    <item>
      <title>Re: Hi Team</title>
      <link>https://community.cisco.com/t5/network-access-control/pushing-ip-sgt-mappings-to-cisco-switch/m-p/4405636#M567398</link>
      <description>&lt;P&gt;Hi!&lt;/P&gt;&lt;P&gt;How would the VRF-aware SGT radius configuration solve this issue and how is this meant to work with SD-access?&lt;/P&gt;&lt;P&gt;Even if i configure my radius server to a separate VRF the static SGT-map configuration pushed is still without the vrf parameter.&lt;BR /&gt;Is there any such parameter within ISE today to define the VRF for the mappings?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 May 2021 19:31:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pushing-ip-sgt-mappings-to-cisco-switch/m-p/4405636#M567398</guid>
      <dc:creator>Cyptic man</dc:creator>
      <dc:date>2021-05-19T19:31:35Z</dc:date>
    </item>
  </channel>
</rss>

