12-08-2021 05:22 PM
Hi,
i just wonder if SDA is able to match a user with multiple SGT? the deployment guide assume a user only carry one SGT?
Regards,
Ivan
Solved! Go to Solution.
12-08-2021 05:58 PM
An IP address (endpoint/user) can only be associated with a single SGT at one time. There is no capability to 'stack' SGTs.
12-08-2021 05:58 PM
An IP address (endpoint/user) can only be associated with a single SGT at one time. There is no capability to 'stack' SGTs.
12-08-2021 06:48 PM - edited 12-08-2021 06:49 PM
Hi Greg,
so the only way is create a bigger SGT group that covers different smaller SGT groups and assign that user in?
Regards,
Ivan
12-09-2021 01:38 AM
hi ivan,
what is the use case of this?
if the user is admin or something then you can have one SGT and allow the access?
the IP address will be assigned from first rule he hits in the cisco ise.
12-09-2021 06:00 PM - edited 12-09-2021 06:01 PM
hi saxenanitesh8522,
say
User A is IT Manager which allow access IT resources and he/she is also a Project Manager of Project A, Project B.
User B is IT admin which allow access IT resources.
User C is a employee and a member of Project A.
User D is a employee and a member of Project B.
So i need to create another SG for User A instead of just put User A in IT resource+Project A+ Project B 's Group?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide