02-18-2019 06:22 AM - edited 03-11-2019 01:55 AM
Hello,
I have configured trustsec vlan enforcement on the Cat9300:
cts role-based sgt-map vlan-list 222 sgt 222
cts role-based enforcement
cts role-based enforcement vlan-list 222
but the command "show cts role-based sgt-map all" shows nothing.
The command "show device-tracking database" shows properly the connected host:
Binding Table has 2 entries, 2 dynamic (limit 100000)
Codes: L - Local, S - Static, ND - Neighbor Discovery, ARP - Address Resolution Protocol, DH4 - IPv4 DHCP, DH6 - IPv6 DHCP, PKT - Other Packet, API - API created
Preflevel flags (prlvl):
0001:MAC and LLA match 0002:Orig trunk 0004:Orig access
0008:Orig trusted trunk 0010:Orig trusted access 0020:DHCP assigned
0040:Cga authenticated 0080:Cert authenticated 0100:Statically assigned
Network Layer Address Link Layer Address Interface vlan prlvl age state Time left
ARP 10.22.22.2 0050.5692.5acb Gi1/0/4 222 0011 8s REACHABLE 292 s try 0
I have tried various IOS XE software 16.10.1, 16.9.2, 16.6.5 but unsuccessfully.
Does anyone have experience with the Trustsec configuration on the Catalyst 9000 series and mapping VLANs to SGT?
Best Regards,
Przemo
02-18-2019 07:57 AM
02-19-2019 01:14 AM
02-19-2019 06:15 AM
02-19-2019 06:41 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide