cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1259
Views
1
Helpful
2
Replies

Cisco ISE SXP

emolstad
Level 1
Level 1

We are currently directly pointing almost all our network devices back to ISE for SXP. We are using a device to ISE SXP peer connection. We are at our max "200" SXP peer limit. Does anyone know if Instead of making SXP peer connection directly to ISE on new switches, if I could point the new switch to a existing switch that is already pointing back to ISE. The goal would be that the switch I connect it to would reach out to ISE for SGT mappings for the switch I put in if the mappings are not already present on the table within the switch. Essentially asking the ISE connected switch to get mappings for the non ISE connected switch. 

1 Accepted Solution

Accepted Solutions

@emolstad yes, you can configure SXP on a switch (listener) to receive bindings from another switch or router (speaker), which learnt the bindings directly from ISE.

https://community.cisco.com/t5/security-knowledge-base/group-based-policy-sxpv5-guide/ta-p/4705541

 

View solution in original post

2 Replies 2

@emolstad yes, you can configure SXP on a switch (listener) to receive bindings from another switch or router (speaker), which learnt the bindings directly from ISE.

https://community.cisco.com/t5/security-knowledge-base/group-based-policy-sxpv5-guide/ta-p/4705541

 

Thank you sir!