<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SGT to IP/subnet binding in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/sgt-to-ip-subnet-binding/m-p/4927726#M584200</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for really quick answer !&lt;BR /&gt;Yes, indeed the matrix (contain my SGACL) is defined (con,figured from DNA Center and pushed to Cisco ISE, to allow my switches using it).&lt;BR /&gt;The default fallback is "Deny IP Log".&lt;BR /&gt;For some of my tags, I have a permit IP (generally, if managed above by a firewall, or for communication to network devices).&lt;BR /&gt;For some tags, I have specific ACLs.&lt;/P&gt;&lt;P&gt;In this case, there is no ACL associated to the SGT used (so 10 and 23), so should be the default "Deny IP Log".&lt;/P&gt;&lt;P&gt;I tested by enabling "Permit IP Log" on the rule from/to Unknown (0) to my second server (10) and I can see the traffic (with 0 not normal indeed).&lt;/P&gt;</description>
    <pubDate>Fri, 22 Sep 2023 10:10:24 GMT</pubDate>
    <dc:creator>dditconsultingbe</dc:creator>
    <dc:date>2023-09-22T10:10:24Z</dc:date>
    <item>
      <title>SGT to IP/subnet binding</title>
      <link>https://community.cisco.com/t5/network-access-control/sgt-to-ip-subnet-binding/m-p/4927709#M584197</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I try to understand a concept of the Cisco TrustSec system.&lt;BR /&gt;On a network, I always used (until now) the binding of SGT to VLAN: this work well.&lt;BR /&gt;For now, I want to go one step further and to statically bind some specific IP to an SGT.&lt;BR /&gt;For example: on the same VLAN, having multiple servers with different SGT to control access.&lt;BR /&gt;In all the case, as far as I know, IP-SGT binding is more priority than VLAN-SGT binding.&lt;/P&gt;&lt;P&gt;All my system is managed by (among others):&lt;BR /&gt;- Cisco Catalyst switches&lt;BR /&gt;- DNA Center&lt;BR /&gt;- Cisco ISE (in RO for SGT, all controlled by DNA)&lt;/P&gt;&lt;P&gt;I want to test the following communication:&lt;BR /&gt;- One server in a VLAN with static SGT mapping (SGT = 10) - IP range = 10.20.0.0/24&lt;BR /&gt;- One server in a VLAN without static SGT mapping (mapping is done after using ISE) - IP range = 10.20.1.0/24&lt;BR /&gt;- The SGT to test is SGT 23&lt;BR /&gt;- SGT 23 is not allow to communicate with SGT 10&lt;/P&gt;&lt;P&gt;Using ISE, I push the SGT-IP mapping on the required switch (so the destination switch, which is also the source switch, of the communication I test). The result command is simple:&amp;nbsp;cts role-based sgt-map 10.20.1.0/24 sgt 23&lt;/P&gt;&lt;P&gt;When I check the result (show cts role-based sgt-map all), I can see:&lt;/P&gt;&lt;P&gt;Active IPv4-SGT Bindings Information&lt;BR /&gt;IP Address SGT Source&lt;BR /&gt;============================================&lt;BR /&gt;10.20.1.0/24 23 CLI&lt;/P&gt;&lt;P&gt;But when I test the communication (basically, a PING), the binding is not applied.&lt;BR /&gt;the system consider that the network 10.20.1.0/24 is Unknown (so SGT 0).&lt;/P&gt;&lt;P&gt;Can you help me understanding this, and explain me how to do this "basic" mapping ?&lt;/P&gt;&lt;P&gt;Thanks in advance for your help !&lt;/P&gt;</description>
      <pubDate>Fri, 22 Sep 2023 09:43:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/sgt-to-ip-subnet-binding/m-p/4927709#M584197</guid>
      <dc:creator>dditconsultingbe</dc:creator>
      <dc:date>2023-09-22T09:43:47Z</dc:date>
    </item>
    <item>
      <title>Re: SGT to IP/subnet binding</title>
      <link>https://community.cisco.com/t5/network-access-control/sgt-to-ip-subnet-binding/m-p/4927716#M584198</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1598566"&gt;@dditconsultingbe&lt;/a&gt; you've pushed the static binding, but do you have the SGACL in place to permit/deny the required traffic?&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-knowledge-base/policy-provisioning-and-operation-in-sda/ta-p/3712744" target="_blank"&gt;https://community.cisco.com/t5/security-knowledge-base/policy-provisioning-and-operation-in-sda/ta-p/3712744&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/cloud-systems-management/dna-center/215516-trustsec-whitelist-model-with-sda.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/cloud-systems-management/dna-center/215516-trustsec-whitelist-model-with-sda.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Sep 2023 09:53:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/sgt-to-ip-subnet-binding/m-p/4927716#M584198</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2023-09-22T09:53:20Z</dc:date>
    </item>
    <item>
      <title>Re: SGT to IP/subnet binding</title>
      <link>https://community.cisco.com/t5/network-access-control/sgt-to-ip-subnet-binding/m-p/4927726#M584200</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for really quick answer !&lt;BR /&gt;Yes, indeed the matrix (contain my SGACL) is defined (con,figured from DNA Center and pushed to Cisco ISE, to allow my switches using it).&lt;BR /&gt;The default fallback is "Deny IP Log".&lt;BR /&gt;For some of my tags, I have a permit IP (generally, if managed above by a firewall, or for communication to network devices).&lt;BR /&gt;For some tags, I have specific ACLs.&lt;/P&gt;&lt;P&gt;In this case, there is no ACL associated to the SGT used (so 10 and 23), so should be the default "Deny IP Log".&lt;/P&gt;&lt;P&gt;I tested by enabling "Permit IP Log" on the rule from/to Unknown (0) to my second server (10) and I can see the traffic (with 0 not normal indeed).&lt;/P&gt;</description>
      <pubDate>Fri, 22 Sep 2023 10:10:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/sgt-to-ip-subnet-binding/m-p/4927726#M584200</guid>
      <dc:creator>dditconsultingbe</dc:creator>
      <dc:date>2023-09-22T10:10:24Z</dc:date>
    </item>
    <item>
      <title>Re: SGT to IP/subnet binding</title>
      <link>https://community.cisco.com/t5/network-access-control/sgt-to-ip-subnet-binding/m-p/4945556#M584767</link>
      <description>&lt;P&gt;Does someone have any news on this ?&lt;/P&gt;</description>
      <pubDate>Sun, 22 Oct 2023 12:57:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/sgt-to-ip-subnet-binding/m-p/4945556#M584767</guid>
      <dc:creator>dditconsultingbe</dc:creator>
      <dc:date>2023-10-22T12:57:32Z</dc:date>
    </item>
  </channel>
</rss>

