Broadcast control with SGTs and microsegmentation

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-30-2022 02:19 AM - edited 06-30-2022 02:37 AM
Hi,
In a Trustsec environment where devices within the same VLAN are not allowed to communicate, layer two traffic like ARP would be also blocked, right? This approach would allow us to have larger subnets without the caveats of the increase on the broadcast traffic that endpoints would have to process, is that correct?
Thanks.
- Labels:
-
Identity Services Engine (ISE)
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-30-2022 06:48 AM
hardware switched traffic will be blocked by SGACLs.
**** please remember to rate useful posts
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-01-2022 11:33 PM
For traffic destined to the switch itself I understand it will be punted to the CPU, but from the endpoints perspective they won't receive other's ARP traffic if not allowed by the matrix, right?

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-05-2022 11:36 PM
Traffic not allowed to destination groups by the TrustSec matrix... should not be allowed (or received) by the destination endpoints.
