cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements
Announcements
Choose one of the topics below to view our ISE Resources to help you on your journey with ISE

This community is for technical, feature, configuration and deployment questions.
For production deployment issues, please contact the TAC! We will not comment or assist with your TAC case in these forums.
Please see How to Ask the Community for Help for other best practices.

1287
Views
0
Helpful
6
Replies
Highlighted
Cisco Employee

ISE -SXP domain construct is not allowing Duplicated IP-SGT mappings

Team , I need some help with SXP config in ISE . We need to duplicate IP-SGT bindings in different VN/VRF's at the borders and we created these via DNAC . In ISE we created different SXP domains one for each VRF at the Borders . However when we map in ISE the IP-SGT bindings to domains first OK while for second we get :

Any feedback or

help highly appreciated

2 ACCEPTED SOLUTIONS

Accepted Solutions
Highlighted
Cisco Employee

Re: ISE -SXP domain construct is not allowing Duplicated IP-SGT mappings

Thank you for reply and looking forward for any feedback .Meanwhile the solution we adopted was to push same IP_SGT binding into multiple domains ....that somehow achieve the same.

Cheers ,

View solution in original post

Highlighted
Cisco Employee

Re: ISE -SXP domain construct is not allowing Duplicated IP-SGT mappings

This is tracked by CSCuz00603

View solution in original post

6 REPLIES 6
Highlighted
Cisco Employee

Re: ISE -SXP domain construct is not allowing Duplicated IP-SGT mappings

This seems a known issue. I will confirm it with the teams.

Highlighted
Cisco Employee

Re: ISE -SXP domain construct is not allowing Duplicated IP-SGT mappings

Thank you for reply and looking forward for any feedback .Meanwhile the solution we adopted was to push same IP_SGT binding into multiple domains ....that somehow achieve the same.

Cheers ,

View solution in original post

Highlighted
Cisco Employee

Re: ISE -SXP domain construct is not allowing Duplicated IP-SGT mappings

Great. I am guessing you meant like this:

Screen Shot 2018-07-05 at 8.40.11 AM.png

Highlighted
Cisco Employee

Re: ISE -SXP domain construct is not allowing Duplicated IP-SGT mappings

This is tracked by CSCuz00603

View solution in original post

Highlighted
Cisco Employee

Re: ISE -SXP domain construct is not allowing Duplicated IP-SGT mappings

Hi Hsing, Krish

Thanks for this link, have not found it before.

Unfortunately my scenario is a bit different then DNA scenario - i can not send the same mapping to two different SXP domains.

That is very interesting that is allowed, while adding "conflicting" mapping not.

I do have a TAC case 685182901 opened and would like to get clarification on our strategy.

If we allow to send the same mapping to multiple SXP domains, why we can not add later the same mapping ? All of them are "duplicated/conflicting". Right ?

It looks like pretty inconsistent approach. Limiting us unnecessarily. Could we have this validation disabled to allow to add duplicated/conflicting mappings ? Do you see any potential risk here ?

 

Thanks,

Michal

 

 

Michal

Highlighted
Cisco Employee

Re: ISE -SXP domain construct is not allowing Duplicated IP-SGT mappings

Agreed, this is all allowed on the switch infrastructure, it's just an ISE implementation anomaly.

You can of course just edit the one mapping entry in ISE and enter more SXP domain destinations.

A fix for individual entries needs to be tracked under CSCuz00603 (multiple exceptions in log with unified ip-sgt functional).