<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: dynamic (via AAA) &amp;amp; static SGT assignment on the port in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/dynamic-via-aaa-amp-static-sgt-assignment-on-the-port/m-p/4823452#M581430</link>
    <description>&lt;P&gt;I'm not sure what change you would be referring to. The output I shared earlier was pulled from my Cat9300 that is configured using IBNS 2.0 (3CPL) framework. The configuration I use on the switch is very similar to what would be pushed by DNAC in an SDA environment.&lt;/P&gt;</description>
    <pubDate>Fri, 28 Apr 2023 01:22:49 GMT</pubDate>
    <dc:creator>Greg Gibbs</dc:creator>
    <dc:date>2023-04-28T01:22:49Z</dc:date>
    <item>
      <title>dynamic (via AAA) &amp; static SGT assignment on the port</title>
      <link>https://community.cisco.com/t5/network-access-control/dynamic-via-aaa-amp-static-sgt-assignment-on-the-port/m-p/4818456#M581312</link>
      <description>&lt;P&gt;Hi Gents&lt;/P&gt;
&lt;P&gt;what take priority between 2 in subject when both static SGT (L2 port-2-sgt) &amp;amp; AAA configured on the port and onboarding endpoint receive different SGT within AAA session?&lt;/P&gt;
&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Sat, 22 Apr 2023 15:30:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dynamic-via-aaa-amp-static-sgt-assignment-on-the-port/m-p/4818456#M581312</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2023-04-22T15:30:26Z</dc:date>
    </item>
    <item>
      <title>Re: dynamic (via AAA) &amp; static SGT assignment on the port</title>
      <link>https://community.cisco.com/t5/network-access-control/dynamic-via-aaa-amp-static-sgt-assignment-on-the-port/m-p/4818986#M581333</link>
      <description>&lt;P&gt;See the binding source priority list here:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/16-9/configuration_guide/cts/b_169_cts_9300_cg/b_169_cts_9300_cg_chapter_01010.html#concept_fx4_nxl_2gb" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/16-9/configuration_guide/cts/b_169_cts_9300_cg/b_169_cts_9300_cg_chapter_01010.html#concept_fx4_nxl_2gb&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Dynamic IP/SGT assignments that happen as a result of an ISE AuthZ Policy are mapped as a LOCAL source on the switch.&lt;BR /&gt;Static IP/SGT mappings that are pushed from ISE to a switch are mapped as a CLI source.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Apr 2023 03:20:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dynamic-via-aaa-amp-static-sgt-assignment-on-the-port/m-p/4818986#M581333</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2023-04-21T03:20:41Z</dc:date>
    </item>
    <item>
      <title>Re: dynamic (via AAA) &amp; static SGT assignment on the port</title>
      <link>https://community.cisco.com/t5/network-access-control/dynamic-via-aaa-amp-static-sgt-assignment-on-the-port/m-p/4819029#M581336</link>
      <description>&lt;H5&gt;Hi Greg&lt;/H5&gt;
&lt;H5&gt;there is even extended one&amp;nbsp;&lt;A href="https://community.cisco.com/t5/network-access-control/trustsec-sgt-binding-priority/td-p/3568368" target="_blank" rel="noopener"&gt;Solved: TrustSec SGT Binding Priority - Cisco Community&amp;nbsp;&lt;/A&gt;&lt;/H5&gt;
&lt;P&gt;but can u please point me to where L2-port mapping &amp;amp; RADIUS-mapping are?&lt;/P&gt;
&lt;H5&gt;&amp;nbsp;1. VLAN—Bindings learned from snooped ARP packets on a VLAN that has VLAN-SGT mapping configured.&lt;/H5&gt;
&lt;H5&gt;2. CLI— Address bindings configured using the IP-SGT form of the cts role-based sgt-map global configuration command.&lt;/H5&gt;
&lt;H5&gt;3. Layer 3 Interface—(L3IF) Bindings added due to FIB forwarding entries that have paths through one or more interfaces with consistent L3IF-SGT mapping or Identity Port Mapping on routed ports.&lt;/H5&gt;
&lt;H5&gt;4. SXP—Bindings learned from SXP peers.&lt;/H5&gt;
&lt;H5&gt;5. IP_ARP—Bindings learned when tagged ARP packets are received on a CTS capable link.&lt;/H5&gt;
&lt;H5&gt;6. LOCAL—Bindings of authenticated hosts which are learned via EPM and device tracking. This type of binding also include individual hosts that are learned via ARP snooping on L2 [I]PM configured ports.&lt;/H5&gt;
&lt;H5&gt;7. SGT CACHING — Bindings learned through the SGT Caching feature by gleaning the inline SGT in the packet.&lt;/H5&gt;
&lt;H5&gt;8. INTERNAL—Bindings between locally configured IP addresses and the device own SGT.&lt;/H5&gt;</description>
      <pubDate>Sat, 22 Apr 2023 15:15:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dynamic-via-aaa-amp-static-sgt-assignment-on-the-port/m-p/4819029#M581336</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2023-04-22T15:15:56Z</dc:date>
    </item>
    <item>
      <title>Re: dynamic (via AAA) &amp; static SGT assignment on the port</title>
      <link>https://community.cisco.com/t5/network-access-control/dynamic-via-aaa-amp-static-sgt-assignment-on-the-port/m-p/4819679#M581346</link>
      <description>&lt;P&gt;i tend to think that AAA-assigned SGT falls under 6. But where does static port-to-sgt belong to?&lt;/P&gt;</description>
      <pubDate>Sat, 22 Apr 2023 15:33:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dynamic-via-aaa-amp-static-sgt-assignment-on-the-port/m-p/4819679#M581346</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2023-04-22T15:33:18Z</dc:date>
    </item>
    <item>
      <title>Re: dynamic (via AAA) &amp; static SGT assignment on the port</title>
      <link>https://community.cisco.com/t5/network-access-control/dynamic-via-aaa-amp-static-sgt-assignment-on-the-port/m-p/4821612#M581375</link>
      <description>&lt;P&gt;If you're talking about statically configuring a Port-SGT mapping using the 'cts manual' command, any IP/SGT binding learned ingress on that port would also be mapped as a LOCAL source.&lt;/P&gt;
&lt;P&gt;Example:&lt;/P&gt;
&lt;PRE&gt;interface GigabitEthernet1/0/22&lt;BR /&gt;cts manual &lt;BR /&gt;&amp;nbsp;policy static sgt 5&lt;/PRE&gt;
&lt;P&gt;There would be no prioritisation between a LOCAL mapped dynamic IP/SGT binding (ISE/AAA server) and a LOCAL mapped Port-SGT binding as mab/dot1x cannot be configured on a switchport that is configured for 'cts manual'. The switch will throw an error if you attempt to configure both.&lt;/P&gt;
&lt;P&gt;Example:&lt;/P&gt;
&lt;PRE&gt;sw5(config-if)#mab&lt;BR /&gt;Command rejected (GigabitEthernet1/0/22): Conflict with CTS.&lt;BR /&gt;CTS must be disabled first&lt;/PRE&gt;</description>
      <pubDate>Tue, 25 Apr 2023 22:14:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dynamic-via-aaa-amp-static-sgt-assignment-on-the-port/m-p/4821612#M581375</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2023-04-25T22:14:44Z</dc:date>
    </item>
    <item>
      <title>Re: dynamic (via AAA) &amp; static SGT assignment on the port</title>
      <link>https://community.cisco.com/t5/network-access-control/dynamic-via-aaa-amp-static-sgt-assignment-on-the-port/m-p/4823282#M581424</link>
      <description>&lt;P&gt;tnx Greg&lt;/P&gt;
&lt;P&gt;i've heard that IBNS2.0+3CPL changes this behaviour somehow... no idea how as had no chances to test&lt;/P&gt;</description>
      <pubDate>Thu, 27 Apr 2023 19:49:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dynamic-via-aaa-amp-static-sgt-assignment-on-the-port/m-p/4823282#M581424</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2023-04-27T19:49:02Z</dc:date>
    </item>
    <item>
      <title>Re: dynamic (via AAA) &amp; static SGT assignment on the port</title>
      <link>https://community.cisco.com/t5/network-access-control/dynamic-via-aaa-amp-static-sgt-assignment-on-the-port/m-p/4823452#M581430</link>
      <description>&lt;P&gt;I'm not sure what change you would be referring to. The output I shared earlier was pulled from my Cat9300 that is configured using IBNS 2.0 (3CPL) framework. The configuration I use on the switch is very similar to what would be pushed by DNAC in an SDA environment.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Apr 2023 01:22:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dynamic-via-aaa-amp-static-sgt-assignment-on-the-port/m-p/4823452#M581430</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2023-04-28T01:22:49Z</dc:date>
    </item>
  </channel>
</rss>

