Feature Information For Cisco Trustsec - Cisco Catalyst 2960-XR Security Configuration Manual

Ios release 15.0 2 ex1
Hide thumbs Also See for Catalyst 2960-XR:
Table of Contents

Advertisement

Configuring Cisco TrustSec
Cisco TrustSec Feature
Security Group Tag (SGT)
SGT Exchange Protocol (SXP)

Feature Information for Cisco TrustSec

This table lists the features in this module and provides links to specific configuration information.
Table 37: Feature Information for Cisco TrustSec
Feature Name
Cisco TrustSec
OL-29434-01
Releases
15.0(2)EX
15.0(2)EX1
Catalyst 2960-XR Switch Security Configuration Guide, Cisco IOS Release 15.0(2)EX1
Feature Information for Cisco TrustSec
Description
An SGT is a 16-bit single label indicating the security
classification of a source in the TrustSec domain. It
is appended to an Ethernet frame or an IP packet.
Security Group Tag Exchange Protocol (SXP). With
SXP, devices that are not TrustSec-hardware-capable
can receive SGT attributes for authenticated users
and devices from the Cisco Identity Services Engine
(ISE) or the Cisco Secure Access Control System
(ACS). The devices can then forward a
sourceIP-to-SGT binding to a
TrustSec-hardware-capable device will tag the source
traffic for SGACL enforcement.
Feature
Information
SXP is introduced
on the Catalyst
2960-X switch.
SXP is introduced
on the Catalyst
2960-XR switch.
375

Advertisement

Table of Contents
loading

Table of Contents