<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Trustsec Inline tagging POC in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/trustsec-inline-tagging-poc/m-p/4633954#M575590</link>
    <description>&lt;P&gt;The link below shows how to use Netflow to monitor inline tagging (no netflow collector is required - you can view the flows on the box). I found it very useful when deploying TrustSec.&lt;/P&gt;&lt;P&gt;hth&lt;BR /&gt;Andy&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;A href="https://community.cisco.com/t5/security-documents/trustsec-troubleshooting-guide/ta-p/3647576#toc-hId-1858751395" target="_blank"&gt;https://community.cisco.com/t5/security-documents/trustsec-troubleshooting-guide/ta-p/3647576#toc-hId-1858751395&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 17 Jun 2022 20:12:34 GMT</pubDate>
    <dc:creator>andrewswanson</dc:creator>
    <dc:date>2022-06-17T20:12:34Z</dc:date>
    <item>
      <title>Trustsec Inline tagging POC</title>
      <link>https://community.cisco.com/t5/network-access-control/trustsec-inline-tagging-poc/m-p/4633448#M575552</link>
      <description>&lt;P&gt;I am in the process setting up cts inline tagging and not seeing the tag on the layer 3 device that is the users gw.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does cts manual and propagate sgt need to be configured one the users interface or just the interface facing the layer 3 device?&lt;/P&gt;
&lt;P&gt;When I enabled it on the trunk port from the switch to the router I lost connectivity to everything on the switch until I enabled the cts manual/propagate sgt on all the sub interfaces.&amp;nbsp; I did a capture on the router and I see packets from the router destined to end user has the CMD field in the trace but packets from the client doesn't have it.&amp;nbsp; When I attempt to add the cts manual/propagate sgt on the users interface I get an error "Command rejected (Gi1/0/8): conflict with Dot1x Auth".&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does the cts command need to be on the base router interface as well as the subs, now I don't see cdp information from the router facing the switch but the switch sees it properly.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Joe&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jun 2022 20:20:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trustsec-inline-tagging-poc/m-p/4633448#M575552</guid>
      <dc:creator>joeharb</dc:creator>
      <dc:date>2022-06-16T20:20:22Z</dc:date>
    </item>
    <item>
      <title>Re: Trustsec Inline tagging POC</title>
      <link>https://community.cisco.com/t5/network-access-control/trustsec-inline-tagging-poc/m-p/4633478#M575556</link>
      <description>&lt;P&gt;You do not configure cts manual or cts propogation on user facing interfaces, only on links between devices that support inline tagging.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If the router interface has sub interfaces, then yes you need cts manual enabled on the parent and each sub interface too.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jun 2022 20:54:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trustsec-inline-tagging-poc/m-p/4633478#M575556</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2022-06-16T20:54:33Z</dc:date>
    </item>
    <item>
      <title>Re: Trustsec Inline tagging POC</title>
      <link>https://community.cisco.com/t5/network-access-control/trustsec-inline-tagging-poc/m-p/4633863#M575583</link>
      <description>&lt;P&gt;Thanks for the reply, I have added the cts manual to the parent interface and I am now seeing good cdp traffic but my capture at the router is not showing the tags on traffic coming back from the switch.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any idea of how to troubleshoot?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Joe&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jun 2022 15:45:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trustsec-inline-tagging-poc/m-p/4633863#M575583</guid>
      <dc:creator>joeharb</dc:creator>
      <dc:date>2022-06-17T15:45:00Z</dc:date>
    </item>
    <item>
      <title>Re: Trustsec Inline tagging POC</title>
      <link>https://community.cisco.com/t5/network-access-control/trustsec-inline-tagging-poc/m-p/4633947#M575587</link>
      <description>&lt;P&gt;If you enable CTS SGT caching on the router you would be able to see if the SGTs are making it to the router.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;cts role-based sgt-caching will enable the feature, and sh cts role-based sgt-map all | inc CACHED will display any ip-sgt bindings learned via inline tagging.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;As for troubleshooting, can you give me an idea about the flow and network devices involved first or a diagram. example;&lt;BR /&gt;endpoint &amp;lt;&amp;gt; 3850 &amp;lt;&amp;gt; 6840 &amp;lt;&amp;gt; 4431&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jun 2022 19:33:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trustsec-inline-tagging-poc/m-p/4633947#M575587</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2022-06-17T19:33:40Z</dc:date>
    </item>
    <item>
      <title>Re: Trustsec Inline tagging POC</title>
      <link>https://community.cisco.com/t5/network-access-control/trustsec-inline-tagging-poc/m-p/4633950#M575588</link>
      <description>I simply doing a ping to a device on the switch. The 2 devices that I am testing the inline are 4300 ISR router trunked to a cat 9300 switch. The device on the switch is a printer and I can it has a sgt of 6. My packet capture on the 4300 shows my traffic with to the printer with CMD but the return does not.&lt;BR /&gt;&lt;BR /&gt;Thanks,&lt;BR /&gt;Joe&lt;BR /&gt;</description>
      <pubDate>Fri, 17 Jun 2022 19:46:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trustsec-inline-tagging-poc/m-p/4633950#M575588</guid>
      <dc:creator>joeharb</dc:creator>
      <dc:date>2022-06-17T19:46:19Z</dc:date>
    </item>
    <item>
      <title>Re: Trustsec Inline tagging POC</title>
      <link>https://community.cisco.com/t5/network-access-control/trustsec-inline-tagging-poc/m-p/4633954#M575590</link>
      <description>&lt;P&gt;The link below shows how to use Netflow to monitor inline tagging (no netflow collector is required - you can view the flows on the box). I found it very useful when deploying TrustSec.&lt;/P&gt;&lt;P&gt;hth&lt;BR /&gt;Andy&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;A href="https://community.cisco.com/t5/security-documents/trustsec-troubleshooting-guide/ta-p/3647576#toc-hId-1858751395" target="_blank"&gt;https://community.cisco.com/t5/security-documents/trustsec-troubleshooting-guide/ta-p/3647576#toc-hId-1858751395&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jun 2022 20:12:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trustsec-inline-tagging-poc/m-p/4633954#M575590</guid>
      <dc:creator>andrewswanson</dc:creator>
      <dc:date>2022-06-17T20:12:34Z</dc:date>
    </item>
    <item>
      <title>Re: Trustsec Inline tagging POC</title>
      <link>https://community.cisco.com/t5/network-access-control/trustsec-inline-tagging-poc/m-p/4650274#M576155</link>
      <description>&lt;P&gt;I have enabled the netflow and I am able to see outbound tags applied but I am still not seeing these upstream.&amp;nbsp; I rebooted the switch last night to enable the dna add on for netflow.&amp;nbsp; I have not physically shutdown the interface between the router and switch, should I attempt that or possible reboot of the router?&amp;nbsp; I have started a TAC case but most of the debugs they have tried are either not valid or not giving much information.&amp;nbsp; Odd part is if I do a capture from the router I see the egress traffic having the metadata but nothing from the switch, if I do a similar capture on the switch I see the packets coming from the router having the metadata but not packets leaving the switch.&amp;nbsp; Not sure why the flow would show the proper tagging but the capture does not.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Joe&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jul 2022 13:34:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trustsec-inline-tagging-poc/m-p/4650274#M576155</guid>
      <dc:creator>joeharb</dc:creator>
      <dc:date>2022-07-14T13:34:29Z</dc:date>
    </item>
    <item>
      <title>Re: Trustsec Inline tagging POC</title>
      <link>https://community.cisco.com/t5/network-access-control/trustsec-inline-tagging-poc/m-p/4650719#M576164</link>
      <description>&lt;P&gt;Is the bug below applicable to your setup?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;A href="https://quickview.cloudapps.cisco.com/quickview/bug/CSCve60357" target="_blank"&gt;https://quickview.cloudapps.cisco.com/quickview/bug/CSCve60357&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jul 2022 18:45:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trustsec-inline-tagging-poc/m-p/4650719#M576164</guid>
      <dc:creator>andrewswanson</dc:creator>
      <dc:date>2022-07-14T18:45:19Z</dc:date>
    </item>
    <item>
      <title>Re: Trustsec Inline tagging POC</title>
      <link>https://community.cisco.com/t5/network-access-control/trustsec-inline-tagging-poc/m-p/4650760#M576165</link>
      <description>We are on 16.12.03a on the switch which appears to be a fixed version.&lt;BR /&gt;</description>
      <pubDate>Thu, 14 Jul 2022 19:29:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trustsec-inline-tagging-poc/m-p/4650760#M576165</guid>
      <dc:creator>joeharb</dc:creator>
      <dc:date>2022-07-14T19:29:44Z</dc:date>
    </item>
    <item>
      <title>Re: Trustsec Inline tagging POC</title>
      <link>https://community.cisco.com/t5/network-access-control/trustsec-inline-tagging-poc/m-p/4771578#M579730</link>
      <description>&lt;PRE&gt;hi Joe&lt;BR /&gt;i've passed throu 16.12.3a 1.5+ years ago with C9300 network advantage .&amp;nbsp;&lt;BR /&gt;apart of cts manual on the uplinks to core i integrated LAN of 29 switches in trustsec domain with ISE by quite simple cts config (apart of turning to pac authorization with my ISE PSNs radius group):&lt;BR /&gt;cts credentials id &amp;lt;switchname&amp;gt; password &amp;lt;cts-pass&amp;gt;&lt;BR /&gt;aaa authorization network TRUSTSEC group auth-radius&lt;BR /&gt;cts authorization list TRUSTSEC&lt;BR /&gt;after that switches started to insert CMD (SGT=0) into authenticated client's frames.&lt;BR /&gt;then when on ISE i've been configuring SGT assignment within AuthZ profiles SGT values in frames changed correspondingly.&lt;BR /&gt;what is your cts configuration?&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Feb 2023 19:13:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trustsec-inline-tagging-poc/m-p/4771578#M579730</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2023-02-08T19:13:37Z</dc:date>
    </item>
    <item>
      <title>Re: Trustsec Inline tagging POC</title>
      <link>https://community.cisco.com/t5/network-access-control/trustsec-inline-tagging-poc/m-p/4772214#M579749</link>
      <description>&lt;P&gt;Just to share my in-line tagging experience.&lt;/P&gt;
&lt;P&gt;Recently I tried in-line tagging between C9800-CL and C8000V and both hosted on a nested ESXi. C9800-CL is on IOS-XE 17.10.1, to get the official DACL support. C8000V was initially 17.6.1a but inline tagging not working from C9800-CL to C8000V. After trying a number of newer IOS-XE releases, it works finally with IOS-XE 17.10.1a.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Feb 2023 16:42:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trustsec-inline-tagging-poc/m-p/4772214#M579749</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2023-02-09T16:42:37Z</dc:date>
    </item>
    <item>
      <title>Re: Trustsec Inline tagging POC</title>
      <link>https://community.cisco.com/t5/network-access-control/trustsec-inline-tagging-poc/m-p/4772235#M579750</link>
      <description>&lt;P&gt;hi&lt;/P&gt;
&lt;P&gt;just for better clarity pls what SW for which platform did u end up to make it work?&lt;/P&gt;</description>
      <pubDate>Thu, 09 Feb 2023 17:13:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trustsec-inline-tagging-poc/m-p/4772235#M579750</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2023-02-09T17:13:52Z</dc:date>
    </item>
    <item>
      <title>Re: Trustsec Inline tagging POC</title>
      <link>https://community.cisco.com/t5/network-access-control/trustsec-inline-tagging-poc/m-p/4772714#M579764</link>
      <description>&lt;P&gt;hi hslai&lt;BR /&gt;could u pls also take a look at 2 other treads? tnx in advance&lt;BR /&gt;&lt;A href="https://community.cisco.com/t5/network-access-control/l2-sgt-treatment-during-routing/td-p/4771878" target="_blank" rel="noopener"&gt;L2-SGT treatment during routing - Cisco Community&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://community.cisco.com/t5/software-defined-access-sd-access/sgt-vxlan-into-l2-sgt-translation-option/td-p/4771900" target="_blank" rel="noopener"&gt;SGT VXLAN into L2-SGT translation option - Cisco Community&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Feb 2023 14:45:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trustsec-inline-tagging-poc/m-p/4772714#M579764</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2023-02-10T14:45:48Z</dc:date>
    </item>
  </channel>
</rss>

