<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SGT Binding Priority (Interface vs. ISE assigned) in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/sgt-binding-priority-interface-vs-ise-assigned/m-p/4444972#M568880</link>
    <description>&lt;P&gt;Greg,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It works if you use IBNS 2.0 configs:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;service-templat APPLY-SGT-100&lt;BR /&gt;sgt 100&lt;BR /&gt;service-templat APPLY-SGT-200&lt;BR /&gt;sgt 200&lt;BR /&gt;!&lt;BR /&gt;policy-map type control subscriber ISE_AUTH_SGT_100&lt;BR /&gt;event authentication-success match-all&lt;BR /&gt;10 class always do-until-failure&lt;BR /&gt;10 activate service-template APPLY-SGT-100&lt;BR /&gt;policy-map type control subscriber ISE_AUTH_SGT_200&lt;BR /&gt;event authentication-success match-all&lt;BR /&gt;10 class always do-until-failure&lt;BR /&gt;10 activate service-template APPLY-SGT-200&lt;BR /&gt;!&lt;BR /&gt;interface gig 1/0/1&lt;BR /&gt;service-policy type control subscriber ISE_AUTH_100&lt;BR /&gt;interface gig 1/0/2&lt;BR /&gt;service-policy type control subscriber ISE_AUTH_200&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ISE will override those settings if you apply SGT tag in ISE.&lt;/P&gt;</description>
    <pubDate>Thu, 05 Aug 2021 15:31:43 GMT</pubDate>
    <dc:creator>paul</dc:creator>
    <dc:date>2021-08-05T15:31:43Z</dc:date>
    <item>
      <title>SGT Binding Priority (Interface vs. ISE assigned)</title>
      <link>https://community.cisco.com/t5/network-access-control/sgt-binding-priority-interface-vs-ise-assigned/m-p/4443470#M568830</link>
      <description>&lt;P&gt;Question on SGT Binding Source Priority. If I statically assign an SGT to a port, but then assign a SGT via ISE how is that resolved. The example would be I want to statically assign to a port but override the static assignment for the phone that may or may not be plugged into that port. I believe static port SGT and ISE assigned SGT fall into the LOCAL category of the SGT Binding Source Priority.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Aug 2021 13:42:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/sgt-binding-priority-interface-vs-ise-assigned/m-p/4443470#M568830</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2021-08-03T13:42:45Z</dc:date>
    </item>
    <item>
      <title>Re: SGT Binding Priority (Interface vs. ISE assigned)</title>
      <link>https://community.cisco.com/t5/network-access-control/sgt-binding-priority-interface-vs-ise-assigned/m-p/4443774#M568835</link>
      <description>&lt;P&gt;I don't believe this scenario is possible. L2 interface SGT static assignment is done using the 'cts manual' configuration on the switchport. The switch will not allow configuration of 'cts manual' on an 802.1x enabled switchport.&lt;/P&gt;
&lt;P&gt;Example:&lt;/P&gt;
&lt;PRE&gt;sw5(config-if)#cts manual 
Command rejected (Gi1/0/26): conflict with Dot1x Auth&lt;/PRE&gt;</description>
      <pubDate>Tue, 03 Aug 2021 23:48:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/sgt-binding-priority-interface-vs-ise-assigned/m-p/4443774#M568835</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2021-08-03T23:48:44Z</dc:date>
    </item>
    <item>
      <title>Re: SGT Binding Priority (Interface vs. ISE assigned)</title>
      <link>https://community.cisco.com/t5/network-access-control/sgt-binding-priority-interface-vs-ise-assigned/m-p/4444972#M568880</link>
      <description>&lt;P&gt;Greg,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It works if you use IBNS 2.0 configs:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;service-templat APPLY-SGT-100&lt;BR /&gt;sgt 100&lt;BR /&gt;service-templat APPLY-SGT-200&lt;BR /&gt;sgt 200&lt;BR /&gt;!&lt;BR /&gt;policy-map type control subscriber ISE_AUTH_SGT_100&lt;BR /&gt;event authentication-success match-all&lt;BR /&gt;10 class always do-until-failure&lt;BR /&gt;10 activate service-template APPLY-SGT-100&lt;BR /&gt;policy-map type control subscriber ISE_AUTH_SGT_200&lt;BR /&gt;event authentication-success match-all&lt;BR /&gt;10 class always do-until-failure&lt;BR /&gt;10 activate service-template APPLY-SGT-200&lt;BR /&gt;!&lt;BR /&gt;interface gig 1/0/1&lt;BR /&gt;service-policy type control subscriber ISE_AUTH_100&lt;BR /&gt;interface gig 1/0/2&lt;BR /&gt;service-policy type control subscriber ISE_AUTH_200&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ISE will override those settings if you apply SGT tag in ISE.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Aug 2021 15:31:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/sgt-binding-priority-interface-vs-ise-assigned/m-p/4444972#M568880</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2021-08-05T15:31:43Z</dc:date>
    </item>
    <item>
      <title>Re: SGT Binding Priority (Interface vs. ISE assigned)</title>
      <link>https://community.cisco.com/t5/network-access-control/sgt-binding-priority-interface-vs-ise-assigned/m-p/4818528#M581318</link>
      <description>&lt;P&gt;Hi&lt;BR /&gt;i dont get how do you pass RADIUS assigned SGT to the above policy. from how i can see this whatever SGT will be sent by RADIUS during successful session on the example ports policy will always set the same SGT (either 100 or 200 depending on port)&lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2023 11:45:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/sgt-binding-priority-interface-vs-ise-assigned/m-p/4818528#M581318</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2023-04-20T11:45:35Z</dc:date>
    </item>
  </channel>
</rss>

