07-23-2017 08:44 PM - edited 03-11-2019 12:52 AM
Understand 2960 switches are able to perform classification (Cisco TrustSec Security Secure Tag )
For example
I have a PCI Server and non-PCI server (same VLAN) connect to same 2960 switch. Is that possible to use Cisco TrustSec on 2960 Switch to control the access between the PCI server and non-PCI server?
Regards.,
Eric
Solved! Go to Solution.
07-24-2017 01:10 AM
Many 2960 switches are capable of Trustsec SGT segmentation and enforcement correction - marking. The complete matrix you should check can be found here:
http://www.cisco.com/c/dam/en/us/solutions/collateral/enterprise-networks/trustsec/platform-capability-matrix.pdf
You can manually configure it or (more commonly) use something like ISE to dynamically assign SGTs based on endpoint identity.
SGACLs would need to be on an upstream device that supports enforcement.
(Thanks to Rob for pointing ot the enforcement distinction.)
07-24-2017 04:18 AM
Correct, the 2960 model switches do not support enforcement.You'd have to enable enforcement upstream on a device that supports enforcement SGACL/SG Firewall.
The 2960 switches do support trustsec SGT classfication, you'd have to use SXP to transport the SGT bindings to the device that will do the enforcement as the 2960's do not support inline tagging.
03-21-2019 11:44 AM
07-24-2017 01:10 AM
Many 2960 switches are capable of Trustsec SGT segmentation and enforcement correction - marking. The complete matrix you should check can be found here:
http://www.cisco.com/c/dam/en/us/solutions/collateral/enterprise-networks/trustsec/platform-capability-matrix.pdf
You can manually configure it or (more commonly) use something like ISE to dynamically assign SGTs based on endpoint identity.
SGACLs would need to be on an upstream device that supports enforcement.
(Thanks to Rob for pointing ot the enforcement distinction.)
07-24-2017 01:11 AM
Checked the complete matrix from the URL you provided. Looks like non of Cisco 2960 switches support SGT enforcement. Can you please confirm?
07-24-2017 04:18 AM
Correct, the 2960 model switches do not support enforcement.You'd have to enable enforcement upstream on a device that supports enforcement SGACL/SG Firewall.
The 2960 switches do support trustsec SGT classfication, you'd have to use SXP to transport the SGT bindings to the device that will do the enforcement as the 2960's do not support inline tagging.
07-26-2017 09:09 AM
ok, back to my example
Is that possible to use Cisco TrustSec on 2960 Switch to control the access between the PCI server and non-PCI server?
I guess the answer is no. Am I correct?
07-26-2017 09:32 AM
If all you have is a 2960 then the answer is no.
You could use private VLANs.
09-16-2017 11:47 AM
I believe the only 2960 only supports "Protected Port" and doesn't support PrivateVLAN fully.
03-20-2019 10:25 AM
@Marvin Rhoads wrote:
If all you have is a 2960 then the answer is no.
You could use private VLANs.
ok, but if 2960 is connected to a 3850, can i use TrustSec on 3850 to control the access between the PCI server and non-PCI server that they are on 2960 Switch?
03-21-2019 11:44 AM
03-22-2019 12:36 AM
i cant install this prm...(
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide