cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2347
Views
10
Helpful
2
Replies

Trustsec SGT - Overlapping Addresses

Eoin.Quinn
Level 1
Level 1

Hi All

 

Would anyone be able to clarify how Trustsec policies handles overlapping addresses?

I'm looking at building out a policy in our environment but we have some things that might need to talk to devices on 1 or 2 internal subnets (eg. 10.1.1.0/24 and 10.1.2.0/24) and then shouldn't be able to talk to anything else internal (eg 10.0.0.0/24) but also needs to talk externally to a dynamic cloud service.

 

I was considering having 1 SGT permitted for the internal allowed, a second denied for private address ranges then permitting unknown.

 

Would this be the correct way to to approach this?

 

Thanks!

1 Accepted Solution

Accepted Solutions

Damien Miller
VIP Alumni
VIP Alumni

As far as IP-SGT overlapping goes, a more specific IP-SGT binding such as a /32 will match over a subnet IP-SGT mapping. 

ex. I can advertise out a /24 subnet mapping, but an endpoint within that subnet can be assigned a specific SGT from ISE during authentication. The /32 will apply assuming it is either carried inline or shared to the correct locations via SXP. 

However I think you are asking more about the creation of overlapping policy goals. Keep in mind that TrustSec on its own is not an IP aware technology, it is addressing agnostic in its enforcement. The only thing that matters is the SGT to SGT flow, what IP's those packets have is not considered in an SGACL. For this reason, you need a specific SGACL for each variation of access policy you wish to create, and as many SGTs to make it work. 

View solution in original post

2 Replies 2

Damien Miller
VIP Alumni
VIP Alumni

As far as IP-SGT overlapping goes, a more specific IP-SGT binding such as a /32 will match over a subnet IP-SGT mapping. 

ex. I can advertise out a /24 subnet mapping, but an endpoint within that subnet can be assigned a specific SGT from ISE during authentication. The /32 will apply assuming it is either carried inline or shared to the correct locations via SXP. 

However I think you are asking more about the creation of overlapping policy goals. Keep in mind that TrustSec on its own is not an IP aware technology, it is addressing agnostic in its enforcement. The only thing that matters is the SGT to SGT flow, what IP's those packets have is not considered in an SGACL. For this reason, you need a specific SGACL for each variation of access policy you wish to create, and as many SGTs to make it work. 

Thanks Damien

That's exactly what I was looking for. Thanks for your help!