cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
165
Views
0
Helpful
4
Replies

Cisco Trustsec Dynamic SGT Assignment

Newbie..9109
Level 1
Level 1

Hi,

There are two types of assignment of SGT : dynamic and static.

Static assignment, ISE will use SXP to inform switch.

How about dynamic (user use 801.x for auth)? Will ISE use SXP or not?

 

4 Replies 4

manvik
Level 3
Level 3

What is your deployment ?? ISE has any PxGrid integration??
ISE can SGT info even for 802.1x users.

I mean when user authenticate using 802.1x will ISE use SXP to inform switch? Or only radius auth no SXP

manvik
Level 3
Level 3

802.1x is an authentication protocol only. it has no relation with SXP.

ISE uses Trustsec/SXP service to inform switches on the SGT tags. Check below doc - https://www.lookingpoint.com/blog/cisco-ise-trustsec-propagation

 

The link you sent to me mention for dynamic SGT assignment, ISE will use Radius authorization to tell the switch about SGT, not using SXP