01-21-2019 06:17 AM
Hello everyone, does anybody know if in a SDA deployment, it is possible to deny traffic inside the same scalable group? The customer is using private VLANs today and wants the same behaivour in a SDA deployment.
Thanks in advance.
Solved! Go to Solution.
01-25-2019 10:55 PM
SDA deployment, it is possible to deny traffic inside the same scalable group?
Yes. You can accomplish this via your Cisco Trustsec matrix in ISE that gets deployed into your trustsec domain in SDA. You have the following options:
permit/deny SGT A <—>SGT A
Or you can leverage L4 SGACLs to specifically allow/deny ports between SGT A members.
Hope this helps.
01-25-2019 10:55 PM
SDA deployment, it is possible to deny traffic inside the same scalable group?
Yes. You can accomplish this via your Cisco Trustsec matrix in ISE that gets deployed into your trustsec domain in SDA. You have the following options:
permit/deny SGT A <—>SGT A
Or you can leverage L4 SGACLs to specifically allow/deny ports between SGT A members.
Hope this helps.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide