Cisco TrustSec Configuration Manual page 114

Table of Contents

Advertisement

cts role-based policy trace
Protocol
Source IP Address
Source Port
Destination IP Address
Destination Port
Result:
==========
Source SGT mapped to Int Gi 1/1 : 6
Destination IP: 10.1.1.2
For <SGT, DGT> pair <6, 5> :
Applicable RBACL : deny_v4_udp-10
The following example traces an HTTP over UDP packet from an IPv6 host:
switch# cts role-based policy trace ipv6 udp host 2001::3 eq 80 host 2003::4 eq 90
Input Qualifiers:
====================
Packet Parameters:
=====================
Protocol
Source IP Address
Source Port
Destination IP Address
Destination Port
Result:
==========
Source
Destination IP: 13::4
For <SGT, DGT> pair <16, 17> :
Applicable RBACL : deny_v6_tcp_udp-10
Related Commands
Command
show cts role-based counters
Cisco TrustSec Configuration Guide
7-28
: UDP
: 10.2.2.1
: 177
: 10.1.1.2
: 80
10 deny udp
: UDP
: 2001::3
: 80
: 2003::4
: 90
IP: 5111::3
SGT: 16
SGT: 17
deny udp sequence 20
SGT: 5
Source:CLI
Source:CLI
Source:CLI
Description
Displays Security Group ACL enforcement statistics.
Chapter 7
Cisco TrustSec Command Summary
OL-22192-01

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents