03-29-2021 05:40 AM
Hey all,
I'm learning how to enforce a network with Trustsec. I understand how to enforce within the fabric, but I don't fully understand enforcing outside the fabric.
My goal is to deny a certain SGT from communicating with anything outside the fabric (towards the internet for example) while allowing other SGTs to do so.
Currently, I'm denying certain services to the internet with my dACL enforcement, using "deny ip any any" at the end.
Is this possible to do this with Trustsec? Do I have to configure this on my perimeter firewall?
Thanks!
Dolev
04-22-2021 10:20 AM
Take a look at the CTS allow-list model (default deny IP) with SDA: Cisco ISE TrustSec Allow-List Model (Default Deny IP) With SDA - Cisco
HTH!
04-22-2021 10:29 AM
That's a serious world of hurt I wouldn't wish on anyone.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide