cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
550
Views
0
Helpful
2
Replies

Cisco Trustsec through 3rd party VPLS / WAN

Ahmed Dockrat
Level 1
Level 1

Hi

 

Is it possible to run Trustsec over a 3rd party VPLS  / Telco switching service.

Have managed to find options with Macsec for setting authentication to happen in unicast to avoid the transit provider trying to process the eapol messages but cant seem to find anything around Trustsec, does Trustsec broadcast or unicast ?

 

The transit/3rd party path is non-cisco which would be acting as a switching layer in the middle.

This is on a cisco 3850 switch

 

Thanks 

2 Replies 2

Hi,

Every device in the path, would need to be configured (if supported) to use cts inline tagging, this will ensure the sgt tag is included in each packet. If the devices do not support inline tagging then you can use SXP to transmit the bindings to the end devices.

 

HTH

balaji.bandi
Hall of Fame
Hall of Fame

I have not done with 3rd party :

 

below guide should help you :

 

https://www.cisco.com/c/dam/en/us/solutions/collateral/borderless-networks/trustsec/C07-730151-00_overview_of_trustSec_og.pdf

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Review Cisco Networking for a $25 gift card