<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE - TrustSec Guide in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-trustsec-guide/m-p/3333613#M550156</link>
    <description>&lt;P&gt;Thank you so much RJ.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I already saw the link and all C2960 is supported. Cisco TrustSec Guideline is very limited that's why is really hard for me on how to start the configuration &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 19 Feb 2018 14:02:06 GMT</pubDate>
    <dc:creator>cammy.busto</dc:creator>
    <dc:date>2018-02-19T14:02:06Z</dc:date>
    <item>
      <title>Cisco ISE - TrustSec Guide</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-trustsec-guide/m-p/3333565#M550150</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Is anyone can share the docs/guideline on how to configure Cisco TrustSec. Also, is Cisco 2960-x is supported with TrustSec? No "cts credentials id" in statement in C2960.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:46:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-trustsec-guide/m-p/3333565#M550150</guid>
      <dc:creator>cammy.busto</dc:creator>
      <dc:date>2020-02-21T18:46:01Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE - TrustSec Guide</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-trustsec-guide/m-p/3333581#M550151</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Check out the &lt;A href="https://www.cisco.com/c/dam/en/us/solutions/collateral/enterprise-networks/trustsec/software-platform-capability-matrix.pdf" target="_self"&gt;TrustSec matrix&lt;/A&gt;, this will help you identify which devices support which features. The 2960x does not support enforcement or inline tagging, only SXP. I would have though the command "cts credentials" would not be available on this model.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;These &lt;A href="https://communities.cisco.com/docs/DOC-64012#jive_content_id_Cisco_TrustSec" target="_self"&gt;links &lt;/A&gt;are useful for TrustSec&lt;/P&gt;</description>
      <pubDate>Mon, 19 Feb 2018 13:32:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-trustsec-guide/m-p/3333581#M550151</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2018-02-19T13:32:52Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE - TrustSec Guide</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-trustsec-guide/m-p/3333586#M550152</link>
      <description>&lt;P&gt;Hi RJI,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for the reply. So the switch configuration is&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;&lt;STRONG&gt;SWITCH# cts sxp connection peer &amp;lt;ISE PSN IP&amp;gt; password default mode local speaker&lt;/STRONG&gt;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Feb 2018 13:38:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-trustsec-guide/m-p/3333586#M550152</guid>
      <dc:creator>cammy.busto</dc:creator>
      <dc:date>2018-02-19T13:38:16Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE - TrustSec Guide</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-trustsec-guide/m-p/3333598#M550153</link>
      <description>&lt;P&gt;The 2960x has to send it's SXP bindings somewhere upstream in order for enforcement to take place, eg on a Distribution layer/WAN layer switch/router, not the ISE PSN (as per your example). The 2960x switch will learn the SGT's when a device/user is authenticated and assigned a SGT, SXP is used to transport the bindings over the network in order for enforcement to take place.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;</description>
      <pubDate>Mon, 19 Feb 2018 13:44:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-trustsec-guide/m-p/3333598#M550153</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2018-02-19T13:44:53Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE - TrustSec Guide</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-trustsec-guide/m-p/3333603#M550154</link>
      <description>&lt;P&gt;Thanks for the reply RJ.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So meaning if this is my diagram&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;C2960 --&amp;gt;C4500x ---&amp;gt;NXS9k &amp;lt;--- ISE PSN&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;C2960 is connected to 4500 - sxp connection peer is C4500&lt;/P&gt;
&lt;P&gt;C4500 will be the enforcer - role-base enforcement&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ISE is connected to Nexus 9k. Traditional nexus 9k is not supported.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Feb 2018 13:51:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-trustsec-guide/m-p/3333603#M550154</guid>
      <dc:creator>cammy.busto</dc:creator>
      <dc:date>2018-02-19T13:51:48Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE - TrustSec Guide</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-trustsec-guide/m-p/3333610#M550155</link>
      <description>&lt;P&gt;Yes, the 4500x supports enforcement so you could peer all 2960x switches to it an enforce on the 4500x.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Check out the platform scalability table in this &lt;A href="https://www.cisco.com/c/dam/en/us/solutions/collateral/enterprise-networks/trustsec/software-system-bulletin.pdf" target="_self"&gt;link &lt;/A&gt;for the number of SXP connections and number of SGT bindings the 4500x supports and whether this will be suitable for your environment.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also make sure the 2960x/4500x are all running the recommended version in the links I provided.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Feb 2018 13:58:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-trustsec-guide/m-p/3333610#M550155</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2018-02-19T13:58:23Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE - TrustSec Guide</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-trustsec-guide/m-p/3333613#M550156</link>
      <description>&lt;P&gt;Thank you so much RJ.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I already saw the link and all C2960 is supported. Cisco TrustSec Guideline is very limited that's why is really hard for me on how to start the configuration &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Feb 2018 14:02:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-trustsec-guide/m-p/3333613#M550156</guid>
      <dc:creator>cammy.busto</dc:creator>
      <dc:date>2018-02-19T14:02:06Z</dc:date>
    </item>
  </channel>
</rss>

