
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-21-2019 06:17 AM
Hello everyone, does anybody know if in a SDA deployment, it is possible to deny traffic inside the same scalable group? The customer is using private VLANs today and wants the same behaivour in a SDA deployment.
Thanks in advance.
Solved! Go to Solution.
- Labels:
-
SD-Access
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-25-2019 10:55 PM
SDA deployment, it is possible to deny traffic inside the same scalable group?
Yes. You can accomplish this via your Cisco Trustsec matrix in ISE that gets deployed into your trustsec domain in SDA. You have the following options:
permit/deny SGT A <—>SGT A
Or you can leverage L4 SGACLs to specifically allow/deny ports between SGT A members.
Hope this helps.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-25-2019 10:55 PM
SDA deployment, it is possible to deny traffic inside the same scalable group?
Yes. You can accomplish this via your Cisco Trustsec matrix in ISE that gets deployed into your trustsec domain in SDA. You have the following options:
permit/deny SGT A <—>SGT A
Or you can leverage L4 SGACLs to specifically allow/deny ports between SGT A members.
Hope this helps.
