01-31-2021 02:12 AM
Dear Experts,
We are working with a customer who requires security group tags or equivalent tagging mechanisms to be implemented in the campus. One of the vendor (not taking its name) claimed they dont support SGT but they can do the tagging and traffic segmentation using VxLAN tags that will be forwarded by their NAC solution.
As per my understanding, VxLAN cant be equivalent or alternative to SGT? am i right?
Solved! Go to Solution.
02-01-2021 12:34 PM
Hello @illusion_rox
Just the mere fact that a vendor is encapsulating the data plane in a VXLAN packet does not mean that they are doing TrustSec. VXLAN is a generic encapsulation method and it depends what the vendor is putting in that header. Cisco will put two things in VXLAN headers that makes the magic of SDA - a VNID (Virtual Network ID) and an SGT (Scalable Group Tag). The VNID tells the receiving device which VRF/NV the data traffic is for (macro segmentation), and the SGT tells us how to treat the data WITHIN the VN (micro-segmentation). VXLAN is the magic that allows customers to finally implement SGT in a network where perhaps it was challenging to do inline SGT tagging, or where it became tricky to send the mapping information via SXP all over the place. It doesn't scale well. VXLAN hides all that mess.
01-31-2021 02:57 AM
01-31-2021 03:19 AM
Thank you. So if customer's compliance is asking for SGT or equivalent tag, will the vendor providing vxlan tagging would comply?
02-01-2021 12:34 PM
Hello @illusion_rox
Just the mere fact that a vendor is encapsulating the data plane in a VXLAN packet does not mean that they are doing TrustSec. VXLAN is a generic encapsulation method and it depends what the vendor is putting in that header. Cisco will put two things in VXLAN headers that makes the magic of SDA - a VNID (Virtual Network ID) and an SGT (Scalable Group Tag). The VNID tells the receiving device which VRF/NV the data traffic is for (macro segmentation), and the SGT tells us how to treat the data WITHIN the VN (micro-segmentation). VXLAN is the magic that allows customers to finally implement SGT in a network where perhaps it was challenging to do inline SGT tagging, or where it became tricky to send the mapping information via SXP all over the place. It doesn't scale well. VXLAN hides all that mess.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide