02-09-2023 12:04 AM - edited 02-13-2023 01:36 AM
Hello Everyone
Could anyone pls shed a light?
Solved! Go to Solution.
02-13-2023 03:27 AM
OK, remember that the 'policy static sgt x trusted' ONLY has the ability to adjust the assigned SGT in the inbound direction (e.g. int1).
In the outbound direction (e.g. int2), the 'cts manual / policy static sgt x trusted' just enables the propagation of the CMD.
So, inbound then on int1, as I've written the command above, the SGT received on the wire will be trusted and will be forwarded out int2 as is.
If the commands on int1 (inbound) are 'cts manual / policy static sgt x', it means do not trust the SGT on the wire and classify the incoming traffic with SGT x instead. This SGT x will be transmitted via CMD out int2.
This topic is covered in a couple of slides in an ISE webinar I presented recently, found on YouTube here: https://www.youtube.com/watch?v=KKbvocNPaOQ&t=34s starting at 11 minutes 15 seconds.
02-11-2023 06:12 PM
@andy!doesnt!like!uucp As you know, I did inline tagging between C9800-CL and C8000V. Although C9800-CL has an SVI for management, the cts configuration goes to the physical interface (in my case, Gi1). For C8000V, each of the sub-interfaces is configured for cts manual and policy static sgt 2 trusted. If an L2 frame has a CMD with SGT, then the SGT is preserved. If no SGT, then SGT2 is sent.
I've also asked my coworker who wrote the Segmentation Strategy guide to take a look of this thread.
02-13-2023 03:27 AM
OK, remember that the 'policy static sgt x trusted' ONLY has the ability to adjust the assigned SGT in the inbound direction (e.g. int1).
In the outbound direction (e.g. int2), the 'cts manual / policy static sgt x trusted' just enables the propagation of the CMD.
So, inbound then on int1, as I've written the command above, the SGT received on the wire will be trusted and will be forwarded out int2 as is.
If the commands on int1 (inbound) are 'cts manual / policy static sgt x', it means do not trust the SGT on the wire and classify the incoming traffic with SGT x instead. This SGT x will be transmitted via CMD out int2.
This topic is covered in a couple of slides in an ISE webinar I presented recently, found on YouTube here: https://www.youtube.com/watch?v=KKbvocNPaOQ&t=34s starting at 11 minutes 15 seconds.
02-13-2023 03:41 AM
Hi Jonothan
highly appreciate your input (inc. reference to utube)! thanks
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide