cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
447
Views
5
Helpful
1
Replies

Do you need Cisco ISE to apply SGT ?

carl.townshend
Level 1
Level 1

Hi All

Do you need Cisco ISE to apply SGTs to switches? or could you get other NAC software to apply them via api's etc ?

Could you apply an SGT manually ?

cheers

1 Accepted Solution

Accepted Solutions

@carl.townshend no you don't need to use ISE, but it's easier. You can send the specific TrustSec (CTS) specific RADIUS Attribute Pairs (AVP) to the switches. https://community.cisco.com/t5/security-knowledge-base/ise-radius-network-access-attributes/ta-p/3616253#toc-hId-725008623

Yes you can apply SGT manually on the switches. https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_usr_cts/configuration/xe-16/sec-usr-cts-xe-16-book/cts-subnet-sgt.html

 

 

View solution in original post

1 Reply 1

@carl.townshend no you don't need to use ISE, but it's easier. You can send the specific TrustSec (CTS) specific RADIUS Attribute Pairs (AVP) to the switches. https://community.cisco.com/t5/security-knowledge-base/ise-radius-network-access-attributes/ta-p/3616253#toc-hId-725008623

Yes you can apply SGT manually on the switches. https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_usr_cts/configuration/xe-16/sec-usr-cts-xe-16-book/cts-subnet-sgt.html