Configuration Guidelines And Limitations - Cisco Catalyst 3560-X Software Configuration Manual

Hide thumbs Also See for Catalyst 3560-X:
Table of Contents

Advertisement

Chapter 1
Cisco TrustSec

Configuration Guidelines and Limitations

The following guidelines and limitations apply to configuring Cisco TrustSec SGT and SGACL on
Catalyst 3750-X and Catalyst 3560-X switches:
OL-25303-03
You cannot statically map an IP-subnet to an SGT. You can only map IP addresses to an SGT. When
you configure IP address-to-SGT mappings, the IP address prefix must be 32.
If a port is configured in Multi-Auth mode, all hosts connecting on that port must be assigned the
same SGT. When a host tries to authenticate, its assigned SGT must be the same as the SGT assigned
to a previously authenticated host. If a host tries to authenticate and its SGT is different from the
SGT of a previously authenticated host, the VLAN port (VP) to which these hosts belong is
error-disabled.
Cisco TrustSec enforcement is supported only on up to eight VLANs on a VLAN-trunk link. If there
are more than eight VLANs configured on a VLAN-trunk link and Cisco TrustSec enforcement is
enabled on those VLANs, the switch ports on those VLAN-trunk links will be error-disabled.
The switch can assign SGT and apply corresponding SGACL to end-hosts based on SXP listening
only if the end-hosts are Layer2 adjacent to the switch.
Port-to-SGT mapping can be configured only on Cisco TrustSec links (that is, switch-to-switch
links). Port-to-SGT mapping cannot be configured on host-to-switch links.
When port-to-SGT mapping is configured on a port, an SGT is assigned to all ingress traffic on that
port. There is no SGACL enforcement for egress traffic on the port.
SGT/SGACL is supported on Cisco Catalyst 3750-X and 3650-X series switches with all network
uplink modules: C3KX-NM-1G, C3KX-NM-10G, C3KX-NM-10GT and C3KX-SM-10G. The
C3KX-SM-10G is only required for MACsec on the uplinks.
The ASCI on Catalyst 3750X has a limitation because of which SGACL enforcement works only for
directly connected clients to the switch.
Catalyst 3750-X and 3560-X Switch Software Configuration Guide
Configuration Guidelines and Limitations
1-3

Advertisement

Table of Contents
loading

This manual is also suitable for:

Catalyst 3750-x

Table of Contents