<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Policy Extended Node not receiving TrustSec SGACLs in Software-Defined Access (SD-Access)</title>
    <link>https://community.cisco.com/t5/software-defined-access-sd-access/policy-extended-node-not-receiving-trustsec-sgacls/m-p/4455037#M1503</link>
    <description>&lt;P&gt;Hi jalejand,&lt;/P&gt;&lt;P&gt;Gi1/0/4 is an AP port which is why it has no SGT assigned:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Clipboard01.jpg" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/128829i9FDC495E8C3AA283/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Clipboard01.jpg" alt="Clipboard01.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Here is the RIB SGT mapping information:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;EX-01#show cts role-based sgt-map al&lt;/STRONG&gt;l&lt;BR /&gt;Active IPv4-SGT Bindings Information&lt;/P&gt;&lt;P&gt;IP Address SGT Source&lt;BR /&gt;============================================&lt;/P&gt;&lt;P&gt;Here are the device-tracking applied interfaces:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;EX-01#show device-tracking policies&lt;/STRONG&gt;&lt;BR /&gt;Target Type Policy Feature Target range&lt;BR /&gt;Gi1/0/1 PORT IPDT_POLICY Device-tracking vlan all&lt;BR /&gt;Gi1/0/2 PORT IPDT_POLICY Device-tracking vlan all&lt;BR /&gt;Gi1/0/4 PORT IPDT_POLICY Device-tracking vlan all&lt;BR /&gt;Gi1/0/5 PORT IPDT_POLICY Device-tracking vlan all&lt;BR /&gt;Gi1/0/6 PORT IPDT_POLICY Device-tracking vlan all&lt;BR /&gt;Gi1/0/8 PORT IPDT_POLICY Device-tracking vlan all&lt;BR /&gt;Gi1/0/13 PORT IPDT_POLICY Device-tracking vlan all&lt;BR /&gt;Gi1/0/17 PORT IPDT_POLICY Device-tracking vlan all&lt;BR /&gt;Gi1/0/18 PORT IPDT_POLICY Device-tracking vlan all&lt;BR /&gt;Gi1/0/19 PORT IPDT_POLICY Device-tracking vlan all&lt;BR /&gt;Gi1/0/20 PORT IPDT_POLICY Device-tracking vlan all&lt;BR /&gt;Gi1/0/21 PORT IPDT_POLICY Device-tracking vlan all&lt;BR /&gt;Gi1/0/22 PORT IPDT_POLICY Device-tracking vlan all&lt;BR /&gt;Gi1/1/1 PORT IPDT_POLICY Device-tracking vlan all&lt;BR /&gt;Gi1/1/2 PORT IPDT_POLICY Device-tracking vlan all&lt;BR /&gt;Gi1/1/3 PORT IPDT_POLICY Device-tracking vlan all&lt;BR /&gt;Gi1/1/4 PORT IPDT_POLICY Device-tracking vlan all&lt;/P&gt;&lt;P&gt;See here that only Gi1/0/5 (the AP port) has any device tracking data, none of the data ports with SGTs assigned do:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;EX-01#show device-tracking data | be Network&lt;/STRONG&gt;&lt;BR /&gt;Network Layer Address Link Layer Address Interface vlan prlvl age state Time left&lt;BR /&gt;ARP 192.168.41.13 70f3.5a80.2ad8 Gi1/0/5 41 0005 11s REACHABLE 300 s&lt;BR /&gt;ND FE80::72F3:5AFF:FE80:2AD8 70f3.5a80.2ad8 Gi1/0/5 41 0005 122s REACHABLE 182 s try 0&lt;/P&gt;&lt;P&gt;Here are the port SGTs:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;EX-01#show platform software fed switch active sgacl port | in 4&lt;/STRONG&gt;&lt;BR /&gt;Gi1/0/3 Enabled 4 No No No No&lt;BR /&gt;Gi1/0/4 Enabled 0 No No No No&lt;BR /&gt;Gi1/0/7 Enabled 4 No No No No&lt;BR /&gt;Gi1/0/9 Enabled 4 No No No No&lt;BR /&gt;Gi1/0/12 Enabled 4 No No No No&lt;BR /&gt;Gi1/0/14 Enabled 4 No No No No&lt;BR /&gt;Gi1/0/15 Enabled 4 No No No No&lt;BR /&gt;Gi1/0/16 Enabled 4 No No No No&lt;BR /&gt;Gi1/0/24 Enabled 8000 Yes Yes No No&lt;BR /&gt;Gi1/1/4 Enabled 0 No No No No&lt;/P&gt;&lt;P&gt;It looks to me that the switch isn't aware of endpoint IP addresses and therefore isn't mapping the SGT to the endpoint...&lt;/P&gt;&lt;P&gt;Any thoughts?&lt;/P&gt;</description>
    <pubDate>Wed, 25 Aug 2021 22:32:58 GMT</pubDate>
    <dc:creator>Joshua Marks</dc:creator>
    <dc:date>2021-08-25T22:32:58Z</dc:date>
    <item>
      <title>Policy Extended Node not receiving TrustSec SGACLs</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/policy-extended-node-not-receiving-trustsec-sgacls/m-p/4454458#M1498</link>
      <description>&lt;P&gt;Hi community,&lt;/P&gt;&lt;P&gt;We have set up a 9200L as a policy extended node in our network, hoping to leverage the micro-segmentation policy defined in ISE and applied to the rest of the network. When verifying that the automated onboarding and provisioning of this switch has TrustSec working, we have found that everything looks good except the SGACLs are requested by the 9200L and pushed by ISE, except the switch is not applying the SGACLs.&lt;/P&gt;&lt;P&gt;Note: all switch configuration has been automated by DNA Center 2.2.2.3, switch is running IOS-XE 17.3.3. No manual configuration has been applied to the switch.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the switch we can see that it has SGTs applied statically to switchports:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;sh run | in interface G|cts|sgt&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/0/1&lt;BR /&gt;cts manual&lt;BR /&gt;policy static sgt 4&lt;BR /&gt;no propagate sgt&lt;BR /&gt;interface GigabitEthernet1/0/2&lt;BR /&gt;cts manual&lt;BR /&gt;policy static sgt 255&lt;BR /&gt;no propagate sgt&lt;BR /&gt;interface GigabitEthernet1/0/3&lt;BR /&gt;cts manual&lt;BR /&gt;policy static sgt 4&lt;BR /&gt;no propagate sgt&lt;BR /&gt;interface GigabitEthernet1/0/4&lt;BR /&gt;cts manual&lt;BR /&gt;policy static sgt 4&lt;BR /&gt;no propagate sgt&lt;/P&gt;&lt;P&gt;-----------------------------brevity&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/0/22&lt;BR /&gt;cts manual&lt;BR /&gt;policy static sgt 4&lt;BR /&gt;no propagate sgt&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When refreshing the cts environment data, we can see it has all of our defined SGTs in its table:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;EX-01#show cts environment-data &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;CTS Environment Data&lt;BR /&gt;====================&lt;BR /&gt;Current state = COMPLETE&lt;BR /&gt;Last status = Successful&lt;BR /&gt;Local Device SGT:&lt;BR /&gt;SGT tag = 0-00:Unknown&lt;BR /&gt;Server List Info:&lt;BR /&gt;Installed list: CTSServerList1-0001, 1 server(s):&lt;BR /&gt;*Server: 192.168.0.220, port 1812, A-ID 12C8BD4B21731585D043636C81DAE9FF&lt;BR /&gt;Status = ALIVE&lt;BR /&gt;auto-test = TRUE, keywrap-enable = FALSE, idle-time = 60 mins, deadtime = 20 secs&lt;BR /&gt;Security Group Name Table:&lt;BR /&gt;0-00:Unknown&lt;BR /&gt;3-05:IoT&lt;BR /&gt;4-20:Employees&lt;BR /&gt;5-35:Lab_Employees&lt;BR /&gt;6-07:Guests&lt;BR /&gt;7-02:Lab_Guests&lt;BR /&gt;8-02:Lab_Isolated_Devices&lt;BR /&gt;9-05:Lab_Grouped_Devices&lt;BR /&gt;10-05:Printers&lt;BR /&gt;11-06:PSK_Devices&lt;BR /&gt;15-07:BYOD&lt;BR /&gt;255-05:Quarantined_Systems&lt;BR /&gt;Environment Data Lifetime = 86400 secs&lt;BR /&gt;Last update time = 23:28:53 UTC Tue Aug 24 2021&lt;BR /&gt;Env-data expires in 0:22:19:52 (dd:hr:mm:sec)&lt;BR /&gt;Env-data refreshes in 0:22:19:52 (dd:hr:mm:sec)&lt;BR /&gt;Cache data applied = NONE&lt;BR /&gt;State Machine is running&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, when refreshing the policy it is only receiving the default SGACL:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;EX-01#show cts role-based permissions&lt;/STRONG&gt;&lt;BR /&gt;IPv4 Role-based permissions from group Invalid to group Invalid:&lt;BR /&gt;Permit IP-00&lt;BR /&gt;RBACL Monitor All for Dynamic Policies : FALSE&lt;BR /&gt;RBACL Monitor All for Configured Policies : FALSE&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is compared to the fabric edge nodes (9300Ls) in our network which show the SGACLs related to their applied SGTs:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;FE-01#sh cts role-based permissions&lt;/STRONG&gt;&lt;BR /&gt;IPv4 Role-based permissions default:&lt;BR /&gt;Permit IP-00&lt;BR /&gt;IPv4 Role-based permissions from group 3:IoT to group 4:Employees:&lt;BR /&gt;Deny IP-00&lt;BR /&gt;IPv4 Role-based permissions from group 4:Employees to group 4:Employees:&lt;BR /&gt;Deny IP-00&lt;BR /&gt;IPv4 Role-based permissions from group 10:Printers to group 4:Employees:&lt;BR /&gt;Permit IP-00&lt;BR /&gt;IPv4 Role-based permissions from group 11:PSK_Devices to group 4:Employees:&lt;BR /&gt;Deny IP-00&lt;BR /&gt;IPv4 Role-based permissions from group 255:Quarantined_Systems to group 4:Employees:&lt;BR /&gt;Deny IP-00&lt;BR /&gt;IPv4 Role-based permissions from group 3:IoT to group 10:Printers:&lt;BR /&gt;Deny IP-00&lt;BR /&gt;IPv4 Role-based permissions from group 4:Employees to group 10:Printers:&lt;BR /&gt;Permit IP-00&lt;BR /&gt;IPv4 Role-based permissions from group 10:Printers to group 10:Printers:&lt;BR /&gt;Permit IP-00&lt;BR /&gt;IPv4 Role-based permissions from group 11:PSK_Devices to group 10:Printers:&lt;BR /&gt;Deny IP-00&lt;BR /&gt;IPv4 Role-based permissions from group 255:Quarantined_Systems to group 10:Printers:&lt;BR /&gt;Deny IP-00&lt;BR /&gt;RBACL Monitor All for Dynamic Policies : FALSE&lt;BR /&gt;RBACL Monitor All for Configured Policies : FALSE&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When we force a policy refresh from the switch, we can see in the ISE live logs that the &lt;EM&gt;policy extended node&lt;/EM&gt; is only being refreshed with the default SGACL:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Clipboard01.jpg" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/128745i26F9E6489D1FA369/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Clipboard01.jpg" alt="Clipboard01.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;Also, when we adjust the TrustSec policy in DNAC and deploy to the fabric, we can see that all switches &lt;STRONG&gt;except&lt;/STRONG&gt; this policy extended node are receiving the updated SGT mappings, despite the fact that it has the relevant SGTs applied to switchports. Note that the device is included in update in ISE (this is configured by DNAC):&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Clipboard02.jpg" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/128746iE9907EC581813CF3/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Clipboard02.jpg" alt="Clipboard02.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;We have also noted that the policy extended node does not have any IP to SGT mappings as we would on a fabric edge switch:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;EX-01#sh cts role-based sgt-map platform | ex 0 0&lt;/STRONG&gt;&lt;BR /&gt;vrf dest htm flags SGT DGID MPLS Last-modified SecsSinceHit&lt;BR /&gt;--- ---- --- ----- --- ---- ---- ------------------------ ------------&lt;BR /&gt;vrf dest htm flags SGT DGID MPLS Last-modified SecsSinceHit&lt;BR /&gt;--- ---- --- ----- --- ---- ---- ------------------------ ------------&lt;/P&gt;&lt;P&gt;Compared to fabric edge switch:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;FE-01# sh cts role-based sgt-map platform | ex 0 0&lt;/STRONG&gt;&lt;BR /&gt;vrf dest htm flags SGT DGID MPLS Last-modified SecsSinceHit&lt;BR /&gt;--- ---- --- ----- --- ---- ---- ------------------------ ------------&lt;BR /&gt;3 192.168.48.26/32 0x7f5080e09678 0x0 10 2 2021/08/23 14:58:01.023 47&lt;BR /&gt;3 192.168.48.42/32 0x7f5080dd5218 0x4 4 1 2021/08/25 01:40:24.374 124&lt;BR /&gt;3 192.168.48.29/32 0x7f5080e230f8 0x4 4 1 2021/08/25 01:40:09.980 134&lt;BR /&gt;3 192.168.48.35/32 0x7f5080dc99b8 0x0 4 1 2021/08/25 01:14:20.382 0&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;In case licensing plays a factor, this is what is applied:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;EX-01#show license summary&lt;/STRONG&gt;&lt;BR /&gt;License Usage:&lt;BR /&gt;License Entitlement Tag Count Status&lt;BR /&gt;-----------------------------------------------------------------------------&lt;BR /&gt;network-advantage (C9200L-NW-A-24) 1 IN USE&lt;BR /&gt;dna-advantage (C9200L-DNA-A-24) 1 IN USE&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Because the configuration is automated and policy extended nodes are supposed to apply and enforce SGT policy, this should "just work". Any assistance is greatly appreciated.&lt;/P&gt;&lt;P&gt;Josh&lt;/P&gt;</description>
      <pubDate>Wed, 25 Aug 2021 01:49:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/policy-extended-node-not-receiving-trustsec-sgacls/m-p/4454458#M1498</guid>
      <dc:creator>Joshua Marks</dc:creator>
      <dc:date>2021-08-25T01:49:59Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Extended Node not receiving TrustSec SGACLs</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/policy-extended-node-not-receiving-trustsec-sgacls/m-p/4454496#M1499</link>
      <description>&lt;P&gt;SGT Rules / SGACLs will only be downloaded on the switch in case SGTs are assigned to endpoints, and it will only download the rules that contain such SGTs as destination, if your SGT mappings are null, then your rules will be also 0.&lt;/P&gt;
&lt;P&gt;As you have static mappings on these ports, I imagine these ports already have endpoints attached to them. &lt;BR /&gt;Can you please get the following from the Extended Node:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;show run&lt;/P&gt;
&lt;P&gt;show version&lt;/P&gt;
&lt;P&gt;show cts pac&lt;BR /&gt;show cts role-based sgt map all&lt;/P&gt;
&lt;P&gt;show device-tracking database&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Aug 2021 04:27:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/policy-extended-node-not-receiving-trustsec-sgacls/m-p/4454496#M1499</guid>
      <dc:creator>jalejand</dc:creator>
      <dc:date>2021-08-25T04:27:05Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Extended Node not receiving TrustSec SGACLs</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/policy-extended-node-not-receiving-trustsec-sgacls/m-p/4454504#M1500</link>
      <description>&lt;P&gt;Hi jalejand, thanks for your response.&lt;/P&gt;&lt;P&gt;The show run is attached. Remaining commands are below.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show version&lt;/STRONG&gt;&lt;BR /&gt;Cisco IOS XE Software, Version 17.03.03&lt;BR /&gt;Cisco IOS Software [Amsterdam], Catalyst L3 Switch Software (CAT9K_LITE_IOSXE), Version 17.3.3, RELEASE SOFTWARE (fc7)&lt;BR /&gt;Technical Support: &lt;A href="http://www.cisco.com/techsupport" target="_blank"&gt;http://www.cisco.com/techsupport&lt;/A&gt;&lt;BR /&gt;Copyright (c) 1986-2021 by Cisco Systems, Inc.&lt;BR /&gt;Compiled Thu 04-Mar-21 08:48 by mcpre&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Cisco IOS-XE software, Copyright (c) 2005-2021 by cisco Systems, Inc.&lt;BR /&gt;All rights reserved. Certain components of Cisco IOS-XE software are&lt;BR /&gt;licensed under the GNU General Public License ("GPL") Version 2.0. The&lt;BR /&gt;software code licensed under GPL Version 2.0 is free software that comes&lt;BR /&gt;with ABSOLUTELY NO WARRANTY. You can redistribute and/or modify such&lt;BR /&gt;GPL code under the terms of GPL Version 2.0. For more details, see the&lt;BR /&gt;documentation or "License Notice" file accompanying the IOS-XE software,&lt;BR /&gt;or the applicable URL provided on the flyer accompanying the IOS-XE&lt;BR /&gt;software.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;ROM: IOS-XE ROMMON&lt;BR /&gt;BOOTLDR: System Bootstrap, Version 17.5.1r [FC4], RELEASE SOFTWARE (P)&lt;/P&gt;&lt;P&gt;PROD-EX-01 uptime is 1 hour, 38 minutes&lt;BR /&gt;Uptime for this control processor is 1 hour, 40 minutes&lt;BR /&gt;System returned to ROM by Power Failure or Unknown at 02:57:07 UTC Sat Jul 3 2021&lt;BR /&gt;System restarted at 03:00:55 UTC Wed Aug 25 2021&lt;BR /&gt;System image file is "flash:cat9k_lite_iosxe.17.03.03.SPA.bin"&lt;BR /&gt;Last reload reason: Power Failure or Unknown&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This product contains cryptographic features and is subject to United&lt;BR /&gt;States and local country laws governing import, export, transfer and&lt;BR /&gt;use. Delivery of Cisco cryptographic products does not imply&lt;BR /&gt;third-party authority to import, export, distribute or use encryption.&lt;BR /&gt;Importers, exporters, distributors and users are responsible for&lt;BR /&gt;compliance with U.S. and local country laws. By using this product you&lt;BR /&gt;agree to comply with applicable laws and regulations. If you are unable&lt;BR /&gt;to comply with U.S. and local laws, return this product immediately.&lt;BR /&gt;&lt;BR /&gt;A summary of U.S. laws governing Cisco cryptographic products may be found at:&lt;BR /&gt;&lt;A href="http://www.cisco.com/wwl/export/crypto/tool/stqrg.html" target="_blank"&gt;http://www.cisco.com/wwl/export/crypto/tool/stqrg.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;If you require further assistance please contact us by sending email to&lt;BR /&gt;export@cisco.com.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Technology Package License Information:&lt;/P&gt;&lt;P&gt;------------------------------------------------------------------------------&lt;BR /&gt;Technology-package Technology-package&lt;BR /&gt;Current Type Next reboot&lt;BR /&gt;------------------------------------------------------------------------------&lt;BR /&gt;network-advantage Smart License network-advantage&lt;BR /&gt;dna-advantage Subscription Smart License dna-advantage&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Smart Licensing Status: Registration Not Applicable/Not Applicable&lt;/P&gt;&lt;P&gt;cisco C9200L-24P-4G (ARM64) processor with 523553K/3071K bytes of memory.&lt;BR /&gt;Processor board ID xxxxxxxxxx&lt;BR /&gt;2 Virtual Ethernet interfaces&lt;BR /&gt;28 Gigabit Ethernet interfaces&lt;BR /&gt;2048K bytes of non-volatile configuration memory.&lt;BR /&gt;1984368K bytes of physical memory.&lt;BR /&gt;819200K bytes of Crash Files at crashinfo:.&lt;BR /&gt;1941504K bytes of Flash at flash:.&lt;/P&gt;&lt;P&gt;Base Ethernet MAC Address : 74:xxxxxxxxxx:00&lt;BR /&gt;Motherboard Assembly Number : xxxxxxxxxx&lt;BR /&gt;Motherboard Serial Number : xxxxxxxxxx&lt;BR /&gt;Model Revision Number : A0&lt;BR /&gt;Motherboard Revision Number : A0&lt;BR /&gt;Model Number : C9200L-24P-4G&lt;BR /&gt;System Serial Number : xxxxxxxxxx&lt;BR /&gt;CLEI Code Number : xxxxxxxxxx&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Switch Ports Model SW Version SW Image Mode&lt;BR /&gt;------ ----- ----- ---------- ---------- ----&lt;BR /&gt;* 1 28 C9200L-24P-4G 17.03.03 CAT9K_LITE_IOSXE BUNDLE&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Configuration register is 0x102&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show cts pac&lt;/STRONG&gt;&lt;BR /&gt;AID: 12C8BDxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxC81DAE9FF&lt;BR /&gt;PAC-Info:&lt;BR /&gt;PAC-type = Cisco Trustsec&lt;BR /&gt;AID: 12C8BDxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxC81DAE9FF&lt;BR /&gt;I-ID: xxxxxxxxxx&lt;BR /&gt;A-ID-Info: Identity Services Engine&lt;BR /&gt;Credential Lifetime: 03:04:58 UTC Tue Nov 23 2021&lt;BR /&gt;PAC-Opaque: 000200B8000300010004001012C8BD4B21731585D043636C81DAE9FF0006009C00030100FAB35E4A6548E5C7BDA16B86E51D601C00000013xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxCAC13373AD1D0F5E6BA2111C5D47C1FEAA1ADC9D330800E4C0E65CDE994D59C4FB12A9F066D603AAD5EBBC603CEB762E23060BB2FF31420558F1&lt;BR /&gt;Refresh timer is set for 12w4d&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show cts role-based sgt-map all&lt;/STRONG&gt;&lt;BR /&gt;Active IPv4-SGT Bindings Information&lt;/P&gt;&lt;P&gt;IP Address SGT Source&lt;BR /&gt;============================================&lt;BR /&gt;Active IPv6-SGT Bindings Information&lt;/P&gt;&lt;P&gt;IP Address SGT Source&lt;BR /&gt;================================================================&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show device-tracking database&lt;/STRONG&gt;&lt;BR /&gt;Binding Table has 2 entries, 2 dynamic (limit 200000)&lt;BR /&gt;Codes: L - Local, S - Static, ND - Neighbor Discovery, ARP - Address Resolution Protocol, DH4 - IPv4 DHCP, DH6 - IPv6 DHCP, PKT - Other Packet, API - API created&lt;BR /&gt;Preflevel flags (prlvl):&lt;BR /&gt;0001:MAC and LLA match 0002:Orig trunk 0004:Orig access&lt;BR /&gt;0008:Orig trusted trunk 0010:Orig trusted access 0020:DHCP assigned&lt;BR /&gt;0040:Cga authenticated 0080:Cert authenticated 0100:Statically assigned&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Network Layer Address Link Layer Address Interface vlan prlvl age state Time left&lt;BR /&gt;ARP 192.168.41.13 70f3.5a80.2ad8 Gi1/0/5 41 0005 7s REACHABLE 303 s&lt;BR /&gt;ND FE80::72F3:5AFF:FE80:2AD8 70f3.5a80.2ad8 Gi1/0/5 41 0005 170s REACHABLE 141 s try 0&lt;/P&gt;</description>
      <pubDate>Wed, 25 Aug 2021 04:53:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/policy-extended-node-not-receiving-trustsec-sgacls/m-p/4454504#M1500</guid>
      <dc:creator>Joshua Marks</dc:creator>
      <dc:date>2021-08-25T04:53:09Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Extended Node not receiving TrustSec SGACLs</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/policy-extended-node-not-receiving-trustsec-sgacls/m-p/4454876#M1501</link>
      <description>&lt;P&gt;Ok, no bindings, CTS config looks good, but you only have one endpoint which seems to be Gi1/0/5 with no SGT config on it:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;interface GigabitEthernet1/0/5&lt;BR /&gt;switchport access vlan 41&lt;BR /&gt;switchport mode access&lt;BR /&gt;device-tracking attach-policy IPDT_POLICY&lt;BR /&gt;load-interval 30&lt;BR /&gt;access-session inherit disable interface-template-sticky&lt;BR /&gt;access-session inherit disable autoconf&lt;BR /&gt;no macro auto processing&lt;BR /&gt;spanning-tree portfast&lt;BR /&gt;spanning-tree bpduguard enable&lt;BR /&gt;service-policy input DNA-MARKING_IN&lt;BR /&gt;service-policy output DNA-dscp#APIC_QOS_Q_OUT&lt;BR /&gt;ip nbar protocol-discovery&lt;BR /&gt;!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What happens if you assign an SGT to 1/0/5 and check if there is a client on device-tracking for that port?&lt;BR /&gt;I would expect to have a new binding on:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;show cts role-based sgt-map all&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For example:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Edge1#show cts role-based sgt-map vrf Campus all&lt;/STRONG&gt;&lt;BR /&gt;%IPv6 protocol is not enabled in VRF Campus&lt;BR /&gt;Active IPv4-SGT Bindings Information&lt;/P&gt;
&lt;P&gt;IP Address SGT Source&lt;BR /&gt;============================================&lt;BR /&gt;&lt;STRONG&gt;172.19.10.12 4 LOCAL&lt;/STRONG&gt; &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In this case, I have an SGT mapping on 172.19.10.12, which is on DeviceTracking (ignore the vrf awareness for simplicity, you will just use the global RIB). But I have two interfaces with static SGT enabled and they are in connected state:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Edge1#show pla sof fed sw active sgacl port | i 4&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Port&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Status&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Port-SGT&amp;nbsp;&amp;nbsp;&amp;nbsp; Trust&amp;nbsp;&amp;nbsp;&amp;nbsp; Propagate IngressCache EgressCache&lt;BR /&gt;-------------------------------------------------------------------------------&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;Te1/0/4&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Enabled&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp; 4&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; No &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp; No&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; No&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; No&lt;BR /&gt;&lt;STRONG&gt;Te1/0/5 &amp;nbsp; &amp;nbsp; Enabled&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; No&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; No&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; No&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; No&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Edge1#show run int te1/0/4 | se cts&lt;/STRONG&gt;&lt;BR /&gt;cts manual&lt;BR /&gt;policy static sgt 4&lt;BR /&gt;no propagate sgt&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Edge1#show run int te1/0/5 | se cts&lt;BR /&gt;&lt;/STRONG&gt;cts manual&lt;BR /&gt;policy static sgt 4&lt;BR /&gt;no propagate sgt&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;But onle 1 of them shows in device-tracking&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Edge1#show device-tracking data int te1/0/4 | be Network&lt;BR /&gt;Network Layer Address Link Layer Address Interface vlan prlvl age state Time left&lt;BR /&gt;API&lt;STRONG&gt; 172.19.10.12&lt;/STRONG&gt; d4e8.801f.4876 Te1/0/4 1021 0005 171s REACHABLE 75 s&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Edge1#show device-tracking data int te1/0/5&lt;BR /&gt;Edge1#&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Aug 2021 17:31:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/policy-extended-node-not-receiving-trustsec-sgacls/m-p/4454876#M1501</guid>
      <dc:creator>jalejand</dc:creator>
      <dc:date>2021-08-25T17:31:34Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Extended Node not receiving TrustSec SGACLs</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/policy-extended-node-not-receiving-trustsec-sgacls/m-p/4455037#M1503</link>
      <description>&lt;P&gt;Hi jalejand,&lt;/P&gt;&lt;P&gt;Gi1/0/4 is an AP port which is why it has no SGT assigned:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Clipboard01.jpg" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/128829i9FDC495E8C3AA283/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Clipboard01.jpg" alt="Clipboard01.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Here is the RIB SGT mapping information:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;EX-01#show cts role-based sgt-map al&lt;/STRONG&gt;l&lt;BR /&gt;Active IPv4-SGT Bindings Information&lt;/P&gt;&lt;P&gt;IP Address SGT Source&lt;BR /&gt;============================================&lt;/P&gt;&lt;P&gt;Here are the device-tracking applied interfaces:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;EX-01#show device-tracking policies&lt;/STRONG&gt;&lt;BR /&gt;Target Type Policy Feature Target range&lt;BR /&gt;Gi1/0/1 PORT IPDT_POLICY Device-tracking vlan all&lt;BR /&gt;Gi1/0/2 PORT IPDT_POLICY Device-tracking vlan all&lt;BR /&gt;Gi1/0/4 PORT IPDT_POLICY Device-tracking vlan all&lt;BR /&gt;Gi1/0/5 PORT IPDT_POLICY Device-tracking vlan all&lt;BR /&gt;Gi1/0/6 PORT IPDT_POLICY Device-tracking vlan all&lt;BR /&gt;Gi1/0/8 PORT IPDT_POLICY Device-tracking vlan all&lt;BR /&gt;Gi1/0/13 PORT IPDT_POLICY Device-tracking vlan all&lt;BR /&gt;Gi1/0/17 PORT IPDT_POLICY Device-tracking vlan all&lt;BR /&gt;Gi1/0/18 PORT IPDT_POLICY Device-tracking vlan all&lt;BR /&gt;Gi1/0/19 PORT IPDT_POLICY Device-tracking vlan all&lt;BR /&gt;Gi1/0/20 PORT IPDT_POLICY Device-tracking vlan all&lt;BR /&gt;Gi1/0/21 PORT IPDT_POLICY Device-tracking vlan all&lt;BR /&gt;Gi1/0/22 PORT IPDT_POLICY Device-tracking vlan all&lt;BR /&gt;Gi1/1/1 PORT IPDT_POLICY Device-tracking vlan all&lt;BR /&gt;Gi1/1/2 PORT IPDT_POLICY Device-tracking vlan all&lt;BR /&gt;Gi1/1/3 PORT IPDT_POLICY Device-tracking vlan all&lt;BR /&gt;Gi1/1/4 PORT IPDT_POLICY Device-tracking vlan all&lt;/P&gt;&lt;P&gt;See here that only Gi1/0/5 (the AP port) has any device tracking data, none of the data ports with SGTs assigned do:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;EX-01#show device-tracking data | be Network&lt;/STRONG&gt;&lt;BR /&gt;Network Layer Address Link Layer Address Interface vlan prlvl age state Time left&lt;BR /&gt;ARP 192.168.41.13 70f3.5a80.2ad8 Gi1/0/5 41 0005 11s REACHABLE 300 s&lt;BR /&gt;ND FE80::72F3:5AFF:FE80:2AD8 70f3.5a80.2ad8 Gi1/0/5 41 0005 122s REACHABLE 182 s try 0&lt;/P&gt;&lt;P&gt;Here are the port SGTs:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;EX-01#show platform software fed switch active sgacl port | in 4&lt;/STRONG&gt;&lt;BR /&gt;Gi1/0/3 Enabled 4 No No No No&lt;BR /&gt;Gi1/0/4 Enabled 0 No No No No&lt;BR /&gt;Gi1/0/7 Enabled 4 No No No No&lt;BR /&gt;Gi1/0/9 Enabled 4 No No No No&lt;BR /&gt;Gi1/0/12 Enabled 4 No No No No&lt;BR /&gt;Gi1/0/14 Enabled 4 No No No No&lt;BR /&gt;Gi1/0/15 Enabled 4 No No No No&lt;BR /&gt;Gi1/0/16 Enabled 4 No No No No&lt;BR /&gt;Gi1/0/24 Enabled 8000 Yes Yes No No&lt;BR /&gt;Gi1/1/4 Enabled 0 No No No No&lt;/P&gt;&lt;P&gt;It looks to me that the switch isn't aware of endpoint IP addresses and therefore isn't mapping the SGT to the endpoint...&lt;/P&gt;&lt;P&gt;Any thoughts?&lt;/P&gt;</description>
      <pubDate>Wed, 25 Aug 2021 22:32:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/policy-extended-node-not-receiving-trustsec-sgacls/m-p/4455037#M1503</guid>
      <dc:creator>Joshua Marks</dc:creator>
      <dc:date>2021-08-25T22:32:58Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Extended Node not receiving TrustSec SGACLs</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/policy-extended-node-not-receiving-trustsec-sgacls/m-p/4455073#M1504</link>
      <description>&lt;P&gt;Exactly, if no DT mapping exists, no SGT map exists either. For now, we can focus on allowing DT to discover the rest of devices.&lt;BR /&gt;Are your endpoints in 1/0/1, 2, 3 etc getting IP via DHCP? If so try enabling DHCP snooping manually so DT can have a table based on DHCP information (I would call this a workaround, ideally you should have an ARP entry on the DT table of the PEN, but who knows how silent are the devices connected there)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;conf t&lt;/P&gt;
&lt;P&gt;&amp;nbsp; no ip dhcp snooping information option&lt;/P&gt;
&lt;P&gt;&amp;nbsp; ip dhcp snooping&lt;/P&gt;
&lt;P&gt;&amp;nbsp; ip dhcp snooping vlan (client vlan)&lt;/P&gt;
&lt;P&gt;&amp;nbsp; int po 1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ip dhcp snooping trust&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then bounce a client port to force it to get an IP again, and if it does (implying that the DHCP snoop config didn't break DHCP as a possibility), after that, check if the client is shown on DT and check its SGT binding.&lt;BR /&gt;&lt;BR /&gt;I'll test this myself on my lab and get back to you &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Aug 2021 00:45:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/policy-extended-node-not-receiving-trustsec-sgacls/m-p/4455073#M1504</guid>
      <dc:creator>jalejand</dc:creator>
      <dc:date>2021-08-26T00:45:35Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Extended Node not receiving TrustSec SGACLs</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/policy-extended-node-not-receiving-trustsec-sgacls/m-p/4455261#M1505</link>
      <description>&lt;P&gt;Hi jalejand,&lt;/P&gt;&lt;P&gt;Your change suggestion appears to have worked well as I can now see the SGT mappings:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;EX-01#show cts role-based sgt-map all&lt;/STRONG&gt;&lt;BR /&gt;Active IPv4-SGT Bindings Information&lt;/P&gt;&lt;P&gt;IP Address SGT Source&lt;BR /&gt;============================================&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;conf t&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp; no ip dhcp snooping information option&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;ip dhcp snooping&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;ip dhcp snooping vlan 41,42,48,50,51,55,56&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;int po 1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp;ip dhcp snooping trust&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;###After a minute or so###&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show cts role-based sgt-map all&lt;/STRONG&gt;&lt;BR /&gt;Active IPv4-SGT Bindings Information&lt;/P&gt;&lt;P&gt;IP Address SGT Source&lt;BR /&gt;============================================&lt;BR /&gt;192.168.50.25 4 LOCAL&lt;BR /&gt;192.168.50.26 4 LOCAL&lt;BR /&gt;192.168.50.27 4 LOCAL&lt;BR /&gt;192.168.50.28 4 LOCAL&lt;BR /&gt;192.168.50.29 4 LOCAL&lt;BR /&gt;192.168.50.30 4 LOCAL&lt;BR /&gt;192.168.50.31 4 LOCAL&lt;/P&gt;&lt;P&gt;Now the switch knows that it has clients with SGTs applied, it has requested the SGACLs from ISE:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show cts role-based permissions&lt;/STRONG&gt;&lt;BR /&gt;IPv4 Role-based permissions default:&lt;BR /&gt;Permit IP-00&lt;BR /&gt;IPv4 Role-based permissions from group 3:IoT to group 4:Employees:&lt;BR /&gt;Deny IP-00&lt;BR /&gt;IPv4 Role-based permissions from group 4:Employees to group 4:Employees:&lt;BR /&gt;Allow_VoIP-01&lt;BR /&gt;IPv4 Role-based permissions from group 10:Printers to group 4:Employees:&lt;BR /&gt;Permit IP-00&lt;BR /&gt;IPv4 Role-based permissions from group 11:PSK_Devices to group 4:Employees:&lt;BR /&gt;Deny IP-00&lt;BR /&gt;IPv4 Role-based permissions from group 255:Quarantined_Systems to group 4:Employees:&lt;BR /&gt;Deny IP-00&lt;BR /&gt;RBACL Monitor All for Dynamic Policies : FALSE&lt;BR /&gt;RBACL Monitor All for Configured Policies : FALSE&lt;/P&gt;&lt;P&gt;Thanks for the help. Why would the automated config pushed by DNAC not include DHCP snooping? Is this normal for policy extended nodes?&lt;/P&gt;&lt;P&gt;Josh&lt;/P&gt;</description>
      <pubDate>Thu, 26 Aug 2021 10:15:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/policy-extended-node-not-receiving-trustsec-sgacls/m-p/4455261#M1505</guid>
      <dc:creator>Joshua Marks</dc:creator>
      <dc:date>2021-08-26T10:15:29Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Extended Node not receiving TrustSec SGACLs</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/policy-extended-node-not-receiving-trustsec-sgacls/m-p/4455462#M1507</link>
      <description>&lt;P&gt;DNAC doesn't push DHCP snooping by default, there&amp;nbsp; are some enhancement bug for this but are not yet customer visibile.&lt;/P&gt;
&lt;P&gt;I would say that for now is normal, I don't have the information about when or how DHCP snooping will be implemented on PENs (or if such enhancement will be resolved as a valid enhancement). However it does two things.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1) It adds the security benefits of DHCP snooping to the extended access layer, which is currently not implemented&lt;/P&gt;
&lt;P&gt;2) By snooping DHCP packets which are not processed by CPU by default, device-tracking gains the ability of a more "trusted" source of information which are DHCP packets + DHCP binding table instead of only relying on ARP to get such entries.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Aug 2021 16:26:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/policy-extended-node-not-receiving-trustsec-sgacls/m-p/4455462#M1507</guid>
      <dc:creator>jalejand</dc:creator>
      <dc:date>2021-08-26T16:26:13Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Extended Node not receiving TrustSec SGACLs</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/policy-extended-node-not-receiving-trustsec-sgacls/m-p/4455659#M1508</link>
      <description>&lt;P&gt;Hi jalejand,&lt;/P&gt;&lt;P&gt;This is my first experience with a policy extended node, but my understanding was that these devices should be able to apply, track and enforce SGTs/contracts between endpoints. If this was not happening on our switch until we enabled DHCP snooping, does that mean the policy extended nodes in general do not enforce TrustSec right now, or is it just something off with our switch?&lt;/P&gt;&lt;P&gt;Thanks again for your great assistance,&lt;/P&gt;&lt;P&gt;Josh&lt;/P&gt;</description>
      <pubDate>Fri, 27 Aug 2021 00:24:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/policy-extended-node-not-receiving-trustsec-sgacls/m-p/4455659#M1508</guid>
      <dc:creator>Joshua Marks</dc:creator>
      <dc:date>2021-08-27T00:24:50Z</dc:date>
    </item>
  </channel>
</rss>

