06-10-2023 02:34 AM
Hi all;
Consider the following scenario:
I this scenario I configured the router with 2 sub-interfaces with the following configuration:
With this configuration everything works fines and the servers can ping each other:
I have also configured the router to interact with ISE:
I do not have enabled "enforcement" on the router:
I use the nearly current version if CSR1000v:
Now I decide to enable "Inline Tagging" on the subinterfaces for the purpose of "SGT over Ethernet" functionality. So, I execute the "cts manual" command on the subinterfaces:
As you can see above, doing so forces the parent interface to bounce.
Now for the testing operation, I encounter the following problem:
As you can see above, any routing operation has failed.
Any ideas?
Thanks
Solved! Go to Solution.
06-11-2023 09:14 AM
I run this scenario on EVE-NG.
According to the following post, because I use subinterfaces on my CSR1000v router, I do not need to execute the "cts manual" command. After executing highlighted command below, the router stared to tag inline packets and advertise them using SXP to ISE.
http://www.network-node.com/blog/2019/3/31/154-digging-into-sgt-bindings-priority-and-sxp
06-10-2023 10:06 AM
With just "cts manual" pings should not be dropped. Have you propagated different SGTs for servers? If yes, check if the traffic (ICMP) between the SGTs is allowed.
06-11-2023 05:12 AM
Thanks for your reply.
As I said, I have not configured any ACL on the switch (local ACL or SGACL).
06-10-2023 10:18 AM
Does the underlying host you're running the 1000v on support inline tagging? Anytime I have seen this done with a virtual router it's with SXP connections because native inline tagging is not supported.
When you configure cts manual you're changing the layer 2 frame ethertype and adding a new Cisco Metadata field in. A lot of Cisco hardware supports this, but this isn't usually the case with anything virtualized.
06-11-2023 09:14 AM
I run this scenario on EVE-NG.
According to the following post, because I use subinterfaces on my CSR1000v router, I do not need to execute the "cts manual" command. After executing highlighted command below, the router stared to tag inline packets and advertise them using SXP to ISE.
http://www.network-node.com/blog/2019/3/31/154-digging-into-sgt-bindings-priority-and-sxp
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide