cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
764
Views
5
Helpful
4
Replies
Beginner

How to periodically refresh SGACL(RBACL) form ISE to the Network Device?

Dear all,

 

I have investigating how to refresh SGACL policy from ISE to Cat3K for instance.

The following URL is related but the document says that it can be refresh on the switch with the command below.

 

#cts refresh policy

 

However if the integrated devices are so many I prefer to update form ISE server.

I think currently PUSH button does not function.

 


[Cisco TrustSec Configuration Guide - Chapter: CTS SGACL Support]
https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_usr_cts/configuration/xe-16/sec-usr-cts-xe-16-book/sec-cts-sgacl.html#id_32643

To refresh the downloaded SGACL policies, perform the following task:

 

I appreciate it there is any related solution.

 

Best Regards,

 

Masanobu Hiyoshi

 

 

 

Everyone's tags (2)
4 REPLIES 4
Highlighted

Re: How to periodically refresh SGACL(RBACL) form ISE to the Network Device?

Hi,

SGT/SGACL data refresh can be changed by modifying below settings under “Administration -> Network Resources -> Network Devices -> Select the device"SGACL refresh.jpg

 

-Aravind
Everyone's tags (2)
Beginner

Re: How to periodically refresh SGACL(RBACL) form ISE to the Network Device?

Hi Aravind,

 

Thank you very much! Well I have verified your proposal. Yes certainly SGACL can be updated.

If you do not mind, I appreciate to let me know each timer recommendation below.

 

Download environment data every 1 day by default

Download peer authorization policy every 1 day by default

Reauthentication every 1 day by default

Download SGACL lists every 1 day by default

 

Best Regards,

 

Masanobu Hiyoshi 

Everyone's tags (1)

Re: How to periodically refresh SGACL(RBACL) form ISE to the Network Device?

Hi Masanobu,

 

Refresh time is completely depends on environment,if new sgts/sgacls are added frequently then every 1 day is fine.

-Aravind
Beginner

Re: How to periodically refresh SGACL(RBACL) form ISE to the Network Device?

Thank you very much!  It must be subject to your precious comment for me.

 

Everyone's tags (1)
CreatePlease to create content
Content for Community-Ad
July's Community Spotlight Awards