<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SDA policy enforcement in Software-Defined Access (SD-Access)</title>
    <link>https://community.cisco.com/t5/software-defined-access-sd-access/sda-policy-enforcement/m-p/4833039#M2326</link>
    <description>&lt;P&gt;short addon to what Flavio said:&lt;/P&gt;
&lt;P&gt;there r 2 places u enforce policies in SDA: 1) SGT-aware Fusion FW - stateful filtering &amp;amp; inspection; 2) FE-layer stateless filtering;&lt;/P&gt;
&lt;P&gt;in case 1)&amp;nbsp; ensure that FW has proper IP-to-SGT mapping to support rules with both SRC&amp;amp;DST defined as SGTs: with good design u will have SRC SGT embedded in L2-frame , but FW will need to lookup DST SGT for the DST IP of the packet. if FW has subscription to PxGrid on ISE, DST SGT can be obtained from DST endpoint session via PxGrid, otherwise u have to configure IP-to-SGT mappings &amp;amp; propagate it to FW via SXP;&lt;/P&gt;
&lt;P&gt;in case 2) if u dont have SRC SGT in the VXLAN header (equivalent of Unknown SGT==0) u must have static IP-to-SGT mapping (SXP is a mean basically), or if u dont have DST endpoint assigned SGT locally (by ISE AuthZ during AAA), u have to use either method of IP-to-SGT mapping (like VLAN-to-SGT).&lt;/P&gt;</description>
    <pubDate>Thu, 11 May 2023 07:41:56 GMT</pubDate>
    <dc:creator>Andrii Oliinyk</dc:creator>
    <dc:date>2023-05-11T07:41:56Z</dc:date>
    <item>
      <title>SDA policy enforcement</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/sda-policy-enforcement/m-p/4832931#M2322</link>
      <description>&lt;P&gt;Hello im still learning about SDA environment i have a question, so in our HQ we deploy SDA infrastructure with policy enforcement on firewall using SGT-IPBASE all the acl on firewall then we want to implement SDA too on our branch but there are no firewall over there, can we enforcement on fusion router ?and how ?&lt;/P&gt;
&lt;P&gt;thank you&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2023 01:27:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/sda-policy-enforcement/m-p/4832931#M2322</guid>
      <dc:creator>reylite</dc:creator>
      <dc:date>2023-05-11T01:27:21Z</dc:date>
    </item>
    <item>
      <title>Re: SDA policy enforcement</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/sda-policy-enforcement/m-p/4832933#M2323</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;There is no requirement for firewall when applying policy enforcement&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Actually the policy enforcement is done by ISE. You create on the DNAC, this is send to ISE via PX Grid and then applied to devices.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Here is the steps.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1. Define SGTs and Policies on DNAC&lt;/SPAN&gt;&lt;BR style="box-sizing: inherit; color: #1b1c1d; font-family: CiscoSans, sans-serif; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 300; letter-spacing: normal; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;" /&gt;&lt;SPAN&gt;2. Deploy, so ISE will get configured by DNAC&lt;/SPAN&gt;&lt;BR style="box-sizing: inherit; color: #1b1c1d; font-family: CiscoSans, sans-serif; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 300; letter-spacing: normal; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;" /&gt;&lt;SPAN&gt;3. ISE will then inform the TrustSec Devices (Fusion/Border/Edges) about a policy change and they will download the new SGTs/Policies&lt;/SPAN&gt;&lt;BR style="box-sizing: inherit; color: #1b1c1d; font-family: CiscoSans, sans-serif; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 300; letter-spacing: normal; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;" /&gt;&lt;BR style="box-sizing: inherit; color: #1b1c1d; font-family: CiscoSans, sans-serif; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 300; letter-spacing: normal; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;" /&gt;&lt;SPAN&gt;If you want to use Static SGT Bindings for Subnets/IP Addresses in the background:&lt;/SPAN&gt;&lt;BR style="box-sizing: inherit; color: #1b1c1d; font-family: CiscoSans, sans-serif; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 300; letter-spacing: normal; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;" /&gt;&lt;SPAN&gt;1. Define SGT/Policy on DNAC&lt;/SPAN&gt;&lt;BR style="box-sizing: inherit; color: #1b1c1d; font-family: CiscoSans, sans-serif; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 300; letter-spacing: normal; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;" /&gt;&lt;SPAN&gt;2. Deploy&lt;/SPAN&gt;&lt;BR style="box-sizing: inherit; color: #1b1c1d; font-family: CiscoSans, sans-serif; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 300; letter-spacing: normal; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;" /&gt;&lt;SPAN&gt;3. Configure static IP-SGT Mapping on ISE&lt;/SPAN&gt;&lt;BR style="box-sizing: inherit; color: #1b1c1d; font-family: CiscoSans, sans-serif; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 300; letter-spacing: normal; orphans: 2; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff; text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;" /&gt;&lt;SPAN&gt;4. TrustSec Devices will download the new SGT and your Devices configured for SXP will download the static IP-SGT Mappings&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2023 01:46:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/sda-policy-enforcement/m-p/4832933#M2323</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2023-05-11T01:46:31Z</dc:date>
    </item>
    <item>
      <title>Re: SDA policy enforcement</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/sda-policy-enforcement/m-p/4833039#M2326</link>
      <description>&lt;P&gt;short addon to what Flavio said:&lt;/P&gt;
&lt;P&gt;there r 2 places u enforce policies in SDA: 1) SGT-aware Fusion FW - stateful filtering &amp;amp; inspection; 2) FE-layer stateless filtering;&lt;/P&gt;
&lt;P&gt;in case 1)&amp;nbsp; ensure that FW has proper IP-to-SGT mapping to support rules with both SRC&amp;amp;DST defined as SGTs: with good design u will have SRC SGT embedded in L2-frame , but FW will need to lookup DST SGT for the DST IP of the packet. if FW has subscription to PxGrid on ISE, DST SGT can be obtained from DST endpoint session via PxGrid, otherwise u have to configure IP-to-SGT mappings &amp;amp; propagate it to FW via SXP;&lt;/P&gt;
&lt;P&gt;in case 2) if u dont have SRC SGT in the VXLAN header (equivalent of Unknown SGT==0) u must have static IP-to-SGT mapping (SXP is a mean basically), or if u dont have DST endpoint assigned SGT locally (by ISE AuthZ during AAA), u have to use either method of IP-to-SGT mapping (like VLAN-to-SGT).&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2023 07:41:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/sda-policy-enforcement/m-p/4833039#M2326</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2023-05-11T07:41:56Z</dc:date>
    </item>
  </channel>
</rss>

