12-14-2021 02:55 PM
Hi Folks
I have a VN in fabric which got two IP pools
and I want block the communication between them using SGT.
Users get authenticated to network with 802.1x using MAB and machine authentication.
However, I don't want to make user groups on ISE but do SGT subnet mappings
I want to give a tags to the subnet so once user connect to network, it cannot with other VLANs in same VRF
How this use case can be achieved?
12-14-2021 11:48 PM
Hello techno,
you can select a default SGT per IP Pool within the host-onboarding configuration. If ISE doesn´t reply with another SGT, SDA will use this default SGT per IP Pool.
12-18-2021 03:27 AM
01-28-2022 03:03 AM
you still need some?
01-16-2022 11:32 AM
Take a peek here as there are a ton of valuable resources shared: https://community.cisco.com/t5/networking-documents/cisco-sd-access-fabric-resources/ta-p/4196271
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide