02-19-2018 05:03 AM - edited 02-21-2020 10:46 AM
Hi,
Is anyone can share the docs/guideline on how to configure Cisco TrustSec. Also, is Cisco 2960-x is supported with TrustSec? No "cts credentials id" in statement in C2960.
Thanks
02-19-2018 05:32 AM
Hi,
Check out the TrustSec matrix, this will help you identify which devices support which features. The 2960x does not support enforcement or inline tagging, only SXP. I would have though the command "cts credentials" would not be available on this model.
These links are useful for TrustSec
02-19-2018 05:38 AM
Hi RJI,
Thanks for the reply. So the switch configuration is
SWITCH# cts sxp connection peer <ISE PSN IP> password default mode local speaker
02-19-2018 05:44 AM
The 2960x has to send it's SXP bindings somewhere upstream in order for enforcement to take place, eg on a Distribution layer/WAN layer switch/router, not the ISE PSN (as per your example). The 2960x switch will learn the SGT's when a device/user is authenticated and assigned a SGT, SXP is used to transport the bindings over the network in order for enforcement to take place.
HTH
02-19-2018 05:51 AM
Thanks for the reply RJ.
So meaning if this is my diagram
C2960 -->C4500x --->NXS9k <--- ISE PSN
C2960 is connected to 4500 - sxp connection peer is C4500
C4500 will be the enforcer - role-base enforcement
ISE is connected to Nexus 9k. Traditional nexus 9k is not supported.
02-19-2018 05:58 AM
Yes, the 4500x supports enforcement so you could peer all 2960x switches to it an enforce on the 4500x.
Check out the platform scalability table in this link for the number of SXP connections and number of SGT bindings the 4500x supports and whether this will be suitable for your environment.
Also make sure the 2960x/4500x are all running the recommended version in the links I provided.
02-19-2018 06:02 AM
Thank you so much RJ.
I already saw the link and all C2960 is supported. Cisco TrustSec Guideline is very limited that's why is really hard for me on how to start the configuration :(
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide