12-14-2021 02:55 PM
Hi Folks
I have a VN in fabric which got two IP pools
and I want block the communication between them using SGT.
Users get authenticated to network with 802.1x using MAB and machine authentication.
However, I don't want to make user groups on ISE but do SGT subnet mappings
I want to give a tags to the subnet so once user connect to network, it cannot with other VLANs in same VRF
How this use case can be achieved?
12-14-2021 11:48 PM
Hello techno,
you can select a default SGT per IP Pool within the host-onboarding configuration. If ISE doesn´t reply with another SGT, SDA will use this default SGT per IP Pool.
12-18-2021 03:27 AM
01-28-2022 03:03 AM
you still need some?
01-16-2022 11:32 AM
Take a peek here as there are a ton of valuable resources shared: https://community.cisco.com/t5/networking-documents/cisco-sd-access-fabric-resources/ta-p/4196271
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: