<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Using Trustsec with Third party NAC solution in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/using-trustsec-with-third-party-nac-solution/m-p/4728014#M578499</link>
    <description>&lt;P&gt;Thanks Rob I wasn’t aware of this, Would you recommend deploying trustsec with forecout tho ?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 25 Nov 2022 10:52:39 GMT</pubDate>
    <dc:creator>Ambuj M</dc:creator>
    <dc:date>2022-11-25T10:52:39Z</dc:date>
    <item>
      <title>Using Trustsec with Third party NAC solution</title>
      <link>https://community.cisco.com/t5/network-access-control/using-trustsec-with-third-party-nac-solution/m-p/4728002#M578496</link>
      <description>&lt;P&gt;Hi Guys&lt;/P&gt;&lt;P&gt;Would it be possible to do segmentation by using Trustsec SGT with a third party NAC solution such as Forescout?&lt;/P&gt;&lt;P&gt;Would we need anything else?&lt;/P&gt;</description>
      <pubDate>Fri, 25 Nov 2022 10:29:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/using-trustsec-with-third-party-nac-solution/m-p/4728002#M578496</guid>
      <dc:creator>carl.townshend</dc:creator>
      <dc:date>2022-11-25T10:29:20Z</dc:date>
    </item>
    <item>
      <title>Re: Using Trustsec with Third party NAC solution</title>
      <link>https://community.cisco.com/t5/network-access-control/using-trustsec-with-third-party-nac-solution/m-p/4728008#M578497</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1117933"&gt;@carl.townshend&lt;/a&gt; yes SGTs can be applied using Forescout - &lt;A href="https://docs.forescout.com/bundle/CounterACT_Administration_Guide_8.0.1/resource/CounterACT_Administration_Guide_8.0.1.pdf" target="_blank"&gt;https://docs.forescout.com/bundle/CounterACT_Administration_Guide_8.0.1/resource/CounterACT_Administration_Guide_8.0.1.pdf&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Forescout configuration would be better discussed in the forescout forums.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Nov 2022 10:43:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/using-trustsec-with-third-party-nac-solution/m-p/4728008#M578497</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-11-25T10:43:28Z</dc:date>
    </item>
    <item>
      <title>Re: Using Trustsec with Third party NAC solution</title>
      <link>https://community.cisco.com/t5/network-access-control/using-trustsec-with-third-party-nac-solution/m-p/4728012#M578498</link>
      <description>&lt;P&gt;Don’t think so, at least I haven’t deployed it, you will need ISE with advantage license and network infrastructure should be comparable with trust-sec compatibility matrix below.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/dam/en/us/solutions/collateral/enterprise-networks/trustsec/policy-platform-capability-matrix.pdf" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/dam/en/us/solutions/collateral/enterprise-networks/trustsec/policy-platform-capability-matrix.pdf&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;additionally getting DNA center appliance would be a good idea as central point of management, automation and enforcement and policy creation for trustsec.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Nov 2022 10:53:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/using-trustsec-with-third-party-nac-solution/m-p/4728012#M578498</guid>
      <dc:creator>Ambuj M</dc:creator>
      <dc:date>2022-11-25T10:53:14Z</dc:date>
    </item>
    <item>
      <title>Re: Using Trustsec with Third party NAC solution</title>
      <link>https://community.cisco.com/t5/network-access-control/using-trustsec-with-third-party-nac-solution/m-p/4728014#M578499</link>
      <description>&lt;P&gt;Thanks Rob I wasn’t aware of this, Would you recommend deploying trustsec with forecout tho ?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Nov 2022 10:52:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/using-trustsec-with-third-party-nac-solution/m-p/4728014#M578499</guid>
      <dc:creator>Ambuj M</dc:creator>
      <dc:date>2022-11-25T10:52:39Z</dc:date>
    </item>
    <item>
      <title>Re: Using Trustsec with Third party NAC solution</title>
      <link>https://community.cisco.com/t5/network-access-control/using-trustsec-with-third-party-nac-solution/m-p/4728018#M578500</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/325330"&gt;@Ambuj M&lt;/a&gt; no, I wouldn't personally recommend deploying trustsec without ISE. A third party vendor is likely to not fully support all the features and support might be an issue.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Nov 2022 10:58:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/using-trustsec-with-third-party-nac-solution/m-p/4728018#M578500</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-11-25T10:58:31Z</dc:date>
    </item>
    <item>
      <title>Re: Using Trustsec with Third party NAC solution</title>
      <link>https://community.cisco.com/t5/network-access-control/using-trustsec-with-third-party-nac-solution/m-p/4728021#M578501</link>
      <description>&lt;P&gt;Also briefly going through the forescout document they talk about assigning sgt as part of authorization, but there is no mention of enforcement based on sgt or some sort of policy matrix.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Nov 2022 11:08:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/using-trustsec-with-third-party-nac-solution/m-p/4728021#M578501</guid>
      <dc:creator>Ambuj M</dc:creator>
      <dc:date>2022-11-25T11:08:19Z</dc:date>
    </item>
    <item>
      <title>Re: Using Trustsec with Third party NAC solution</title>
      <link>https://community.cisco.com/t5/network-access-control/using-trustsec-with-third-party-nac-solution/m-p/4738213#M578820</link>
      <description>&lt;P&gt;Anyone may assign an SGT in a RADIUS session - it's just a RADIUS Vendor-Specific Attribute (VSA) from Cisco that any vendor may implement in a RADIUS authorization response. That's the beauty of standard protocols like RADIUS.&lt;/P&gt;
&lt;P&gt;But how does your network device(s) know about your SGTs and SGACLs in the first place???&lt;/P&gt;
&lt;P&gt;The hard part is going to be initial and ongoing updates of the TrustSec Matrix with all of the SGTs and SGACLs to your network devices.&amp;nbsp; That would be a very tedious process to manually update all of those across all of your network devices without ISE. &lt;EM&gt;This&lt;/EM&gt; is the special sauce with ISE.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;See our recent ISE Webinar:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A class="" title="https://youtu.be/rq7bSgO_GPg" href="https://youtu.be/rq7bSgO_GPg" data-from-md="" target="_blank"&gt;Group-Based Segmentation Basics&lt;/A&gt;&lt;BR /&gt;Speaker: Jonathan Eaves, Technical Marketing Engineer&lt;CODE&gt;&lt;/CODE&gt;&lt;BR /&gt;&lt;A title="https://youtu.be/rq7bSgO_GPg&amp;amp;t=1378s" href="https://youtu.be/rq7bSgO_GPg&amp;amp;t=1378s" data-from-md="" target="_blank"&gt;22:58&lt;/A&gt; Dynamic Group Policy Download from ISE for Enforcement at Egress&lt;BR /&gt;&lt;A title="https://youtu.be/rq7bSgO_GPg&amp;amp;t=1563s" href="https://youtu.be/rq7bSgO_GPg&amp;amp;t=1563s" data-from-md="" target="_blank"&gt;26:03&lt;/A&gt; Enforcement Demo&lt;/P&gt;</description>
      <pubDate>Wed, 14 Dec 2022 00:47:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/using-trustsec-with-third-party-nac-solution/m-p/4738213#M578820</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2022-12-14T00:47:01Z</dc:date>
    </item>
  </channel>
</rss>

