Check the downloaded SGACL at the egress Edge node.
- From the Cisco DNA Center, navigate to the Policy tab.
- Click the Group-Based Access Control tile.
- Ensure that the SGACl is correctly defined.
- From Identity Services Engine (ISE), click Work Centers.
- Navigate to TrustSec Policy.
Ensure that the Cisco DNA Center group-based access control information is in sync with the ISE TrustSec matrix.
Run the following command to ensure that the correct SGACL is downloaded from ISE.
show cts role-based permissions
Run the following command to confirm whether the counters for the appropriate SGACL are updated.
show cts role-based counters