<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TrustSec SGT tags and Scalable Groups in Software-Defined Access (SD-Access)</title>
    <link>https://community.cisco.com/t5/software-defined-access-sd-access/trustsec-sgt-tags-and-scalable-groups/m-p/5291588#M4058</link>
    <description>&lt;P&gt;"&lt;SPAN&gt;So if I assign a tag like “IT-DEPARTMENT” to some devices, will they all be in the same scalable group?"&lt;BR /&gt;yes they will be in the same SG&lt;BR /&gt;"Can I, on the other hand, assign them to different scalable groups and apply policies even if they are on the same subnet without the need of deploying VACLs, MAC ACLs, etc?"&lt;BR /&gt;u can assign endpoint whatever SG of your choice. but any time endpoint may belong to single SG only. u dont need VACL/MACL/etc as soon as you properly map you filtering intent to egress policy where both SRC &amp;amp; DST SGTs must be available for policing device (egress switch|router|FW)&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 17 May 2025 11:24:13 GMT</pubDate>
    <dc:creator>Andrii Oliinyk</dc:creator>
    <dc:date>2025-05-17T11:24:13Z</dc:date>
    <item>
      <title>TrustSec SGT tags and Scalable Groups</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/trustsec-sgt-tags-and-scalable-groups/m-p/5291583#M4056</link>
      <description>&lt;P&gt;Hi, everyone.&lt;/P&gt;
&lt;P&gt;I've recently began studying SD-Access and my book mentions the following regarding the policy plane (TrustSec).&lt;/P&gt;
&lt;P&gt;■&lt;EM&gt; Scalable group: A scalable group is a group of endpoints with similar policies. The&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;SD-Access policy plane assigns every endpoint (host) to a scalable group using&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;TrustSec SGT tags. Assignment to a scalable group can be either static per fabric edge&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;port or using dynamic authentication through AAA or RADIUS using Cisco ISE. The&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;same scalable group is configured on all fabric edge and border nodes. Scalable groups&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;can be defined in Cisco DNA Center and/or Cisco ISE and are advertised through&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Cisco TrustSec.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;As for the scalable groups. It says that it’s a group of endpoints that have the same policies and that the group is assigned using tags. So if I assign a tag like “IT-DEPARTMENT” to some devices, will they all be in the same scalable group? Can I, on the other hand, assign them to different scalable groups and apply policies even if they are on the same subnet without the need of deploying VACLs, MAC ACLs, etc?&lt;/P&gt;
&lt;P&gt;Thank you.&lt;BR /&gt;David&lt;/P&gt;</description>
      <pubDate>Sat, 17 May 2025 10:26:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/trustsec-sgt-tags-and-scalable-groups/m-p/5291583#M4056</guid>
      <dc:creator>Mitrixsen</dc:creator>
      <dc:date>2025-05-17T10:26:00Z</dc:date>
    </item>
    <item>
      <title>Re: TrustSec SGT tags and Scalable Groups</title>
      <link>https://community.cisco.com/t5/software-defined-access-sd-access/trustsec-sgt-tags-and-scalable-groups/m-p/5291588#M4058</link>
      <description>&lt;P&gt;"&lt;SPAN&gt;So if I assign a tag like “IT-DEPARTMENT” to some devices, will they all be in the same scalable group?"&lt;BR /&gt;yes they will be in the same SG&lt;BR /&gt;"Can I, on the other hand, assign them to different scalable groups and apply policies even if they are on the same subnet without the need of deploying VACLs, MAC ACLs, etc?"&lt;BR /&gt;u can assign endpoint whatever SG of your choice. but any time endpoint may belong to single SG only. u dont need VACL/MACL/etc as soon as you properly map you filtering intent to egress policy where both SRC &amp;amp; DST SGTs must be available for policing device (egress switch|router|FW)&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 17 May 2025 11:24:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/software-defined-access-sd-access/trustsec-sgt-tags-and-scalable-groups/m-p/5291588#M4058</guid>
      <dc:creator>Andrii Oliinyk</dc:creator>
      <dc:date>2025-05-17T11:24:13Z</dc:date>
    </item>
  </channel>
</rss>

