<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SDA || VN and IP range not propagated to ISE in Software-Defined Access (SD-Access)</title>
    <link>https://community.cisco.com/t5/software-defined-access-sd-access/sda-vn-and-ip-range-not-propagated-to-ise/m-p/4968175#M2827</link>
    <description>&lt;P&gt;as far as i know DNAC doesnt communicate SGT-to-IP_subnet mapping to ISE. I've heard ISE can publish SGT-to-IP_subnet mapping to PxGrid "via SXP-topic". Also ISE has calls via its API enabling caller to populate ISE;s TrustSec component "IP SGT static mapping" with target stuff. No idea why DNAC doesnt leverage it&lt;/P&gt;</description>
    <pubDate>Wed, 29 Nov 2023 11:36:20 GMT</pubDate>
    <dc:creator>Andrii Oliinyk</dc:creator>
    <dc:date>2023-11-29T11:36:20Z</dc:date>
    <item>
      <title>SDA || VN and IP range not propagated to ISE</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/sda-vn-and-ip-range-not-propagated-to-ise/m-p/4967986#M2826</link>
      <description>&lt;P&gt;Hey all!&lt;/P&gt;&lt;P&gt;I'm having a bit of a brain lock to be honest and I'm surprised how there is no easy way to find documentation mentioning this ( or I'm just clueless) but, I'm having an issue with VN I created and mapped an SGT to, is not propagated to ISE.&lt;/P&gt;&lt;P&gt;DNA&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://2.3.3.7/" target="_blank" rel="noopener"&gt;2.3.3.7&lt;/A&gt;&lt;BR /&gt;ISE 3.2 p4&lt;/P&gt;&lt;P&gt;VN Is created under Provision &amp;gt; SD-ACCESS&amp;gt;Virtual Networks&lt;BR /&gt;SGT is created under Policy &amp;gt; Group based access control &amp;gt; Security Groups&lt;BR /&gt;SGT Is mapped to IP Pool and VN under Provision &amp;gt; Fabric &amp;gt; Host Onboarding &amp;gt; Virtual networks &amp;gt; IP pool added and SGT assigned.&lt;/P&gt;&lt;P&gt;Now, this process seem to have changed over the time as previously in 1.3 releases you mapped SGT directly to VN under Policy Tab so I'm assuming I could be missing something . I don't have anything as a reference to see how this process goes but I'm assuming that when this mapping is done on DNA ( and DNA is the management for trustsec between DNAC and ISE) DNA should push this mapping to ISE.&lt;/P&gt;&lt;P&gt;So in Workspaces &amp;gt; Trustsec &amp;gt; Component &amp;gt; Security Groups when I Click on SGT It should POP up a window which will show SGT And VN and IP pool this SGT is mapped to. Perhaps even it should show under IP SGT Static Mapping page. But this is missing.&lt;/P&gt;&lt;P&gt;SGT's are provisioned on ISE when created however, so the integration of ISE and DNA should be fine.&lt;/P&gt;&lt;P&gt;Am I missing something or should this indeed be provisioned and the fact it's not means I should open a case with TAC?&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Wed, 29 Nov 2023 08:32:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/sda-vn-and-ip-range-not-propagated-to-ise/m-p/4967986#M2826</guid>
      <dc:creator>Lebowski1991</dc:creator>
      <dc:date>2023-11-29T08:32:43Z</dc:date>
    </item>
    <item>
      <title>Re: SDA || VN and IP range not propagated to ISE</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/sda-vn-and-ip-range-not-propagated-to-ise/m-p/4968175#M2827</link>
      <description>&lt;P&gt;as far as i know DNAC doesnt communicate SGT-to-IP_subnet mapping to ISE. I've heard ISE can publish SGT-to-IP_subnet mapping to PxGrid "via SXP-topic". Also ISE has calls via its API enabling caller to populate ISE;s TrustSec component "IP SGT static mapping" with target stuff. No idea why DNAC doesnt leverage it&lt;/P&gt;</description>
      <pubDate>Wed, 29 Nov 2023 11:36:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/sda-vn-and-ip-range-not-propagated-to-ise/m-p/4968175#M2827</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2023-11-29T11:36:20Z</dc:date>
    </item>
    <item>
      <title>Re: SDA || VN and IP range not propagated to ISE</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/sda-vn-and-ip-range-not-propagated-to-ise/m-p/4970005#M2830</link>
      <description>&lt;P&gt;Hi!&lt;/P&gt;&lt;P&gt;I actually found the issue.&lt;/P&gt;&lt;P&gt;”&lt;SPAN&gt;When &lt;/SPAN&gt;&lt;SPAN class=""&gt;Cisco DNA Center&lt;/SPAN&gt;&lt;SPAN&gt; 2.3.3 or later is integrated with &lt;/SPAN&gt;&lt;SPAN class=""&gt;Cisco ISE&lt;/SPAN&gt;&lt;SPAN&gt; 3.2or later, security groups are not associated with virtual networks, and the &lt;/SPAN&gt;&lt;SPAN class=""&gt;Virtual Networks&lt;/SPAN&gt;&lt;SPAN&gt; field is not displayed for these releases. However, if you are using &lt;/SPAN&gt;&lt;SPAN class=""&gt;Cisco ISE&lt;/SPAN&gt;&lt;SPAN&gt;3.1 or earlier, the security group and virtual network association details are displayed&lt;/SPAN&gt;&lt;SPAN&gt;”&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I knew It was there originally &lt;span class="lia-unicode-emoji" title=":face_with_tears_of_joy:"&gt;😂&lt;/span&gt;.&lt;/P&gt;&lt;P&gt;I actually went through this guide when I was looking for an answer but must have missed this note.&lt;/P&gt;&lt;P&gt;Source:&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/cloud-systems-management/network-automation-and-management/dna-center/2-3-7/user_guide/b_cisco_dna_center_ug_2_3_7/m_configure-group-based-access-control-policies-and-analytics.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/cloud-systems-management/network-automation-and-management/dna-center/2-3-7/user_guide/b_cisco_dna_center_ug_2_3_7/m_configure-group-based-access-control-policies-and-analytics.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;So basically now all you need to Add VN and SGT when configuring Authorization Profile and thats about it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Dec 2023 19:15:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/sda-vn-and-ip-range-not-propagated-to-ise/m-p/4970005#M2830</guid>
      <dc:creator>Lebowski1991</dc:creator>
      <dc:date>2023-12-01T19:15:19Z</dc:date>
    </item>
  </channel>
</rss>

