cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3177
Views
1
Helpful
5
Replies

trustsec SXP listener for ISE

xili5
Cisco Employee
Cisco Employee

Hi,

If "Add radius mappings into SXP IP SGT mapping table" is checked on SXP setting, does it mean ISE will automatically learn all dynamic IP-SGT mappings through radius process? If yes, is there any scenarios that ISE is configured as SXP listener to learn mapping from other devices, like switch/WLC/firewall?

br,

Xin

1 Accepted Solution

Accepted Solutions

hslai
Cisco Employee
Cisco Employee

Yes, ISE can learn mappings from SXP peers. ISE can also have static mappings and propagate them via SXP.

ISE can classify RADIUS sessions with SGT, as Nidhi mentioned, but the network devices need to be able to support SGT as a session field and can either enforce it on the network devices themselves, or propagate via SXP or in-line.

Moving this discussion to TrustSec.

View solution in original post

5 Replies 5

Nidhi
Cisco Employee
Cisco Employee

Researching !

xili5
Cisco Employee
Cisco Employee

I also find that when there is no SXP peer avaible for ISE, SXP mapping is blank. When I add a SXP device in listener mode, some SXP mapping entries which are shown as "learned by Session" appeared. It seems that we must have a SXP device, then SXP mapping could appear, even the entries are learned by radius session, not learned by SXP peer.

So is it normal behaviour for ISE?

Nidhi
Cisco Employee
Cisco Employee

Basically after an endpoint   authenticates with ISE , ISE sends SGT to the device. The switch learns the IP address of the endpoint and sends IP-SGT information to ISE via SXP.

xili5
Cisco Employee
Cisco Employee

Hi Nidhi,

I'd like to confirm that if ISE could have IP-SGT mapping information through radius session without SXP.

hslai
Cisco Employee
Cisco Employee

Yes, ISE can learn mappings from SXP peers. ISE can also have static mappings and propagate them via SXP.

ISE can classify RADIUS sessions with SGT, as Nidhi mentioned, but the network devices need to be able to support SGT as a session field and can either enforce it on the network devices themselves, or propagate via SXP or in-line.

Moving this discussion to TrustSec.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: