cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
713
Views
7
Helpful
3
Replies

TrustSec DNAC, ISE and ACI with Multiple Tenants

MFloresG5
Level 1
Level 1

Architecture:

  • ACI Implementation with Multiple Tenants ( v5.2.(7f)
  • Each Tenant with a L3Out
  • Single ISE Cluster Instance managing Auth/Authz request for all the organizations/Tenants
  • DNAC v 2.3.3.6

Scenario:

We are implementing TrustSec whowever everywhere we look for integration documentation - it is stated that TrustSec with ACI + ISE only supports single Tenant with single L3Out.

Has anybody implemented TrustSec with DNAC + ISe + ACI with multiple tenants and multiple L3Outs if so how?

  • How about ACI with SR-MPLS utilizing Infra Tenant to inject EEPGs and IEPGs exchange with ISE
  • How about the common tenant?
  • How about the infra tenant?

 

3 Replies 3

Hello andy!doesnt!like!uucp 

Thank you so much for your reply. We did reviewed this integration and we are definitely able to observer the limitations. I really appreciate you taken the time to guide us.

jedolphi
Cisco Employee
Cisco Employee

Hi can't be done today through an SD-Access/ISE-ACI integration. You can use an Cisco Secure Firewall between SD-Access and ACI domains to implement SGT-EPG policy, if that's suitable. ACI Endpoint Update App loads EPG:IP into firewall. ISE loads SGTs into firewall. More information here: https://www.ciscolive.com/on-demand/on-demand-library.html?search=BRKSEC-2116#/session/1670019637340001nvJI

 

Review Cisco Networking for a $25 gift card