07-01-2019 07:58 PM - edited 02-21-2020 11:07 AM
Attempting to enable SGT inline tagging configuration on the Supervisor Engine interfaces with Hardware Supervisor Engine - VS-SUP2T-10G Modules - WS-X6848-TX-2T (with DFC4)
resulted in the following message:
“CTS configuration could not be activated (Te x/x): CTS SGT Propagation not allowed by platform
Reason: Incompatible Linecards 61xx and/or 67xx CFC/DFC present. Please power down the Incompatible Linecards as they will not come up on next reload/OIR or configure either CTS Egress or CTS Ingress.”
Although I don’t have the modules listed in this message, I assuming that it also includes the WS-X6848-TX-2T, WS-X6824-SFP-2T, C6800-48P-TX, and C6800-48P-TX-XL modules.
Example interface configuration
interface Te x/x | Fo x/x
switchport
switchport mode dynamic desirable
cts manual
propagate sgt
policy static sgt 10001 trusted
channel-group 1 mode active
Also, on Egress Reflector Mode
CTS Egress Reflector Mode uses Catalyst Switch Port Analyzer (SPAN) to reflect traffic from a CTS-incapable module to the Supervisor Engine 2T/6T for SGT assignment and insertion. A CTS egress reflector is implemented on a distribution switch with Layer 3 uplinks, where the CTS-incapable module is connected to access layer switches. CTS egress reflector supports Centralized Forwarding Cards (CFCs) and Distributed Forwarding Cards (DFCs).
Using <platform cts egress> (and reload) and then attempting to test the SGT inline tagging configuration on the Supervisor Engine interfaces with Hardware Supervisor Engine - C6800-SUP6T Modules - C6800-48P-TX-XL (with DFC4-XL)
“CTS configuration could not be activated (Fo x/x): CTS SGT Propagation not allowed by platform
Reason: SGT Propagation not allowed on non-routed ports in CTS Egress mode”
This seems supported on Sup 2T and 6T on the 6500, please any pointers will be greatly appreciated.
Solved! Go to Solution.
07-01-2019 08:43 PM
07-01-2019 08:19 PM
07-01-2019 08:29 PM
Yes, I did.
According to the Cisco TrustSec Software-Defined Segmentation Platform and Capability Matrix Release 6.4, SGT inline tagging over Ethernet & SGT over MACsec is supported on the Catalyst 6500-E/6807-XL chassis with Supervisor Engine 2T & 6T and the following modules.
07-01-2019 08:43 PM
07-02-2019 07:39 AM
Thanks Damien, I see the caveat in the document hslai provided. maybe we add these caveat to the updated TrustSec compatibility matrix.
04-13-2022 08:55 AM
Hello everyone,
Have the same issue here, so to be clear the solution is to change your port from L2 trunk to L3 ports.....correct?
07-01-2019 08:31 PM
07-02-2019 05:28 AM
Please what about Sup 6T ? I see the caveats on egress reflection mode Damien mention
07-02-2019 07:05 AM
Compare Models Catalyst 6500 Series Switches on Sup Engines - Cisco shows they differing mainly in DFC, MSFC, and PFC. The CTS support should be much the same as 2T.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide