02-13-2023 10:57 PM
Hi,
We are considering the use of a SGT to port map on every access switchport to enforce the traffic of the non-authenticated devices. Once the device is authenticated it will get a dynamic SGT that will override the static mapping. The question is, how can we allow the traffic in the worst scenario when the PSNs are down. Before Trustsec we have the the concept of critical VLAN. Is there a similar "critical SGT" in TrustSec?
Regards.
Solved! Go to Solution.
02-14-2023 02:12 AM
@AntonioMacia yes there is a "Critical SGT", you can use IBNS 2.0 to assign a critical SGT when the AAA server is down.
You can create a local SGACL to reference that critical SGT. An SGACL learned from ISE would have priority over a local SGACL, so the local SGACL would only apply when ISE is down. - https://www.cisco.com/c/en/us/support/docs/cloud-systems-management/dna-center/215516-trustsec-whitelist-model-with-sda.html#anc18
The guide above is for a DNAC SDA deployment, but no reason why you cannot manually create everything locally if not in an SDA environment.
02-14-2023 02:12 AM
@AntonioMacia yes there is a "Critical SGT", you can use IBNS 2.0 to assign a critical SGT when the AAA server is down.
You can create a local SGACL to reference that critical SGT. An SGACL learned from ISE would have priority over a local SGACL, so the local SGACL would only apply when ISE is down. - https://www.cisco.com/c/en/us/support/docs/cloud-systems-management/dna-center/215516-trustsec-whitelist-model-with-sda.html#anc18
The guide above is for a DNAC SDA deployment, but no reason why you cannot manually create everything locally if not in an SDA environment.
02-20-2023 03:29 AM
Thank you Rob.
That was the information I was looking for.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide