<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: About Default egress rule in Software-Defined Access (SD-Access)</title>
    <link>https://community.cisco.com/t5/software-defined-access-sd-access/about-default-egress-rule/m-p/3878271#M185</link>
    <description>&lt;P&gt;Thank you for the information.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Currently, “&lt;EM&gt;cts role-based enforcement&lt;/EM&gt;” is set to the physical port. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Neither “&lt;EM&gt;cts role-based enforcement&lt;/EM&gt;” nor “&lt;EM&gt;no cts role-based enforcement&lt;/EM&gt;” is set for VLAN. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;And, the following two lines are input in configuration mode: &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&amp;nbsp;cts role-based enforcement &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&amp;nbsp;cts role-based enforcement vlan-list 1023 &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;By setting &lt;SPAN&gt;“&lt;EM&gt;no cts role-based enforcement&lt;/EM&gt;”&lt;/SPAN&gt; to the physical port, does it mean that the default EgressPolicy can be reflected only on the overlay without affecting the underlay?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 24 Jun 2019 04:54:52 GMT</pubDate>
    <dc:creator>Keisuke.I</dc:creator>
    <dc:date>2019-06-24T04:54:52Z</dc:date>
    <item>
      <title>About Default egress rule</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/about-default-egress-rule/m-p/3875768#M180</link>
      <description>&lt;P&gt;If FinalCatchAllRule in Default egress rule is set to &lt;EM&gt;Deny_IP&lt;/EM&gt; on TrustSec EgressPolicy Matrix screen, it seems that not only overlay but also underlay communication will be denied.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to know the setting that only overlay communication is rejected by default without affecting underlay communication.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jun 2019 03:52:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/about-default-egress-rule/m-p/3875768#M180</guid>
      <dc:creator>Keisuke.I</dc:creator>
      <dc:date>2019-06-19T03:52:12Z</dc:date>
    </item>
    <item>
      <title>Re: About Default egress rule</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/about-default-egress-rule/m-p/3876993#M183</link>
      <description>&lt;P&gt;As long as you have "no cts role-based enforcement" on the port config or no cts configured at all on the port you there shouldnt be a problem.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jun 2019 18:57:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/about-default-egress-rule/m-p/3876993#M183</guid>
      <dc:creator>ldanny</dc:creator>
      <dc:date>2019-06-20T18:57:54Z</dc:date>
    </item>
    <item>
      <title>Re: About Default egress rule</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/about-default-egress-rule/m-p/3878271#M185</link>
      <description>&lt;P&gt;Thank you for the information.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Currently, “&lt;EM&gt;cts role-based enforcement&lt;/EM&gt;” is set to the physical port. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Neither “&lt;EM&gt;cts role-based enforcement&lt;/EM&gt;” nor “&lt;EM&gt;no cts role-based enforcement&lt;/EM&gt;” is set for VLAN. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;And, the following two lines are input in configuration mode: &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&amp;nbsp;cts role-based enforcement &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&amp;nbsp;cts role-based enforcement vlan-list 1023 &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;By setting &lt;SPAN&gt;“&lt;EM&gt;no cts role-based enforcement&lt;/EM&gt;”&lt;/SPAN&gt; to the physical port, does it mean that the default EgressPolicy can be reflected only on the overlay without affecting the underlay?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jun 2019 04:54:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/about-default-egress-rule/m-p/3878271#M185</guid>
      <dc:creator>Keisuke.I</dc:creator>
      <dc:date>2019-06-24T04:54:52Z</dc:date>
    </item>
  </channel>
</rss>

