02-13-2023 06:50 PM
Architecture:
Scenario:
We are implementing TrustSec whowever everywhere we look for integration documentation - it is stated that TrustSec with ACI + ISE only supports single Tenant with single L3Out.
Has anybody implemented TrustSec with DNAC + ISe + ACI with multiple tenants and multiple L3Outs if so how?
02-13-2023 11:53 PM - edited 02-14-2023 01:34 AM
looks like there is no chances:
Solved: ISE 3.0 Integration with ACI - Limitations? - Cisco Community
02-18-2023 10:06 AM
Hello andy!doesnt!like!uucp
Thank you so much for your reply. We did reviewed this integration and we are definitely able to observer the limitations. I really appreciate you taken the time to guide us.
02-14-2023 10:59 PM
Hi can't be done today through an SD-Access/ISE-ACI integration. You can use an Cisco Secure Firewall between SD-Access and ACI domains to implement SGT-EPG policy, if that's suitable. ACI Endpoint Update App loads EPG:IP into firewall. ISE loads SGTs into firewall. More information here: https://www.ciscolive.com/on-demand/on-demand-library.html?search=BRKSEC-2116#/session/1670019637340001nvJI
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide