- Finding Feature Information
- Information About Cisco TrustSec Interface-to-SGT Mapping
- How to Configure Cisco TrustSec Interface-to-SGT Mapping
- Configuration Examples for Cisco TrustSec Interface-to-SGT Mapping
- Additional References for Cisco TrustSec Interface-to-SGT Mapping
- Feature Information for Cisco TrustSec Interface-to-SGT Mapping
Cisco TrustSec
Interface-to-SGT Mapping
The Cisco TrustSec Interface-to-SGT Mapping feature binds all traffic on a Layer 3 ingress interface to a security group tag (SGT). Once this mapping is implemented, Cisco TrustSec can use the SGT to segregate traffic from various logical Layer 3 ingress interfaces.
- Finding Feature Information
- Information About Cisco TrustSec Interface-to-SGT Mapping
- How to Configure Cisco TrustSec Interface-to-SGT Mapping
- Configuration Examples for Cisco TrustSec Interface-to-SGT Mapping
- Additional References for Cisco TrustSec Interface-to-SGT Mapping
- Feature Information for Cisco TrustSec Interface-to-SGT Mapping
Finding Feature Information
Your software release may not support all the features documented in this module. For the latest caveats and feature information, see Bug Search Tool and the release notes for your platform and software release. To find information about the features documented in this module, and to see a list of the releases in which each feature is supported, see the feature information table.
Use Cisco Feature Navigator to find information about platform support and Cisco software image support. To access Cisco Feature Navigator, go to www.cisco.com/go/cfn. An account on Cisco.com is not required.
Information About Cisco TrustSec Interface-to-SGT Mapping
Interface-to-SGT Mapping
The configured SGT tag is assigned to all traffic on the Layer 3 ingress interface and can be used for inline tagging and policy enforcement.
Binding Source Priorities
-
CLI—Bindings configured using the cts role-based sgt-map sgt command.
-
L3IF—Bindings added due to FIB forwarding entries that have paths through one or more interfaces with consistent Layer 3 Interface to SGT (L3IF-SGT) mapping or identity port mapping on routed ports.
-
SXP—Bindings learned from SGT Exchange Protocol (SXP) peers.
-
LOCAL—Bindings of authenticated hosts that are learned via Cisco Enterprise Policy Manager (EPM) and device tracking. This type of binding also includes individual hosts that are learned via Address Resolution Protocol (ARP) snooping on ports configured with the Layer 2 port mirroring feature.
-
INTERNAL—Bindings between locally configured IP addresses and the devices own SGT.
How to Configure Cisco TrustSec Interface-to-SGT Mapping
Configuring Layer 3 Interface-to-SGT Mapping
1.
enable
2.
configure
terminal
3.
interface
type
slot/port
4.
cts role-based sgt-map sgt
sgt-number
5.
end
DETAILED STEPS
Verifying Layer 3 Interface-to-SGT Mapping
1.
enable
2.
show cts role-based sgt-map all
DETAILED STEPS
Configuration Examples for Cisco TrustSec Interface-to-SGT Mapping
Example: Configuring Layer 3 Interface-to-SGT Mapping
The following example shows the security group tag (SGT) mapping configuration for the Layer 3 ingress interface:
Device> enable Device# configure terminal Device(config)# interface gigabitEthernet 0/0 Device(config-if)# cts role-based sgt-map sgt 77 Device(config-if)# end
Additional References for Cisco TrustSec Interface-to-SGT Mapping
Related Documents
Related Topic |
Document Title |
---|---|
Cisco IOS commands |
|
Security commands |
|
Cisco TrustSec and SXP configuration |
Technical Assistance
Description |
Link |
---|---|
The Cisco Support website provides extensive online resources, including documentation and tools for troubleshooting and resolving technical issues with Cisco products and technologies. To receive security and technical information about your products, you can subscribe to various services, such as the Product Alert Tool (accessed from Field Notices), the Cisco Technical Services Newsletter, and Really Simple Syndication (RSS) Feeds. Access to most tools on the Cisco Support website requires a Cisco.com user ID and password. |
Feature Information for Cisco TrustSec Interface-to-SGT Mapping
The following table provides release information about the feature or features described in this module. This table lists only the software release that introduced support for a given feature in a given software release train. Unless noted otherwise, subsequent releases of that software release train also support that feature.
Use Cisco Feature Navigator to find information about platform support and Cisco software image support. To access Cisco Feature Navigator, go to www.cisco.com/go/cfn. An account on Cisco.com is not required.
Feature Name |
Releases |
Feature Information |
---|---|---|
Cisco TrustSec Interface-to-SGT Mapping |
15.4(2)T |
The Cisco TrustSec Interface-to-SGT Mapping feature binds all traffic on a Layer 3 ingress interface to a security group tag (SGT). Once this mapping is implemented, Cisco TrustSec can use the SGT to segregate traffic from various logical Layer 3 ingress interfaces. In Cisco IOS Release 15.4(2)T, support was added for the Cisco Integrated Services Router Generation 2 (Cisco ISR G2). The following command was introduced or modified: cts role-based sgt-map sgt. |