- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-16-2018 08:32 AM - edited 03-11-2019 01:32 AM
Is there a capability to give a switch port a default SGT assignment? Similar to how we can have a default-acl on a switch port in closed mode. Having trouble with a 50 line default-acl on a 2960 switch. Would like to use SGT to reduces the size of that ACL but need to have the port assign a default SGT.
Solved! Go to Solution.
- Labels:
-
Segmentation
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-16-2018 09:58 AM
Hi, TrustSec works by classifying endpoints/users (ultimately IP's) into groups.
You can see our capability matrix to see what sort of classifications your version of 2960 supports:
As that platform doesn't support Port:SGT you could use IP:SGT, VLAN:SGT or Subnet:SGT to put traffic ingressing that port into a group.
That would be the default behaviour and if an endpoint were to be dynamically authenticated through that port instead then that would take precedence over the static IP, VLAN or Subnet mapping.
Hope that helps.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-16-2018 09:58 AM
Hi, TrustSec works by classifying endpoints/users (ultimately IP's) into groups.
You can see our capability matrix to see what sort of classifications your version of 2960 supports:
As that platform doesn't support Port:SGT you could use IP:SGT, VLAN:SGT or Subnet:SGT to put traffic ingressing that port into a group.
That would be the default behaviour and if an endpoint were to be dynamically authenticated through that port instead then that would take precedence over the static IP, VLAN or Subnet mapping.
Hope that helps.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
04-16-2018 05:53 PM
Thanks.
Sam
