
C H A P T E R
27-1
Cisco Nexus 1000V Troubleshooting Guide, Release 5.2(1)SV3(1.1)
OL-31593-01
27
Cisco TrustSec
This chapter describes how to identify and resolve problems that might occur when configuring Cisco
TrustSec and includes the following sections:
•
Information About Cisco TrustSec, page 27-1
•
Cisco TrustSec Troubleshooting Commands, page 27-1
•
Problems with Cisco TrustSec, page 27-5
Information About Cisco TrustSec
The Cisco TrustSec security architecture builds secure networks by establishing clouds of trusted
network devices. Each device in the cloud is authenticated by its neighbors. Communication on the links
between devices in the cloud is secured with a combination of encryption, message integrity checks, and
data-path replay protection mechanisms.
Cisco TrustSec also uses the device and user identification information acquired during authentication
for classifying, or coloring, the packets as they enter the network. This packet classification is
maintained by tagging packets on ingress to the Cisco TrustSec network so that they can be properly
identified for the purpose of applying security and other policy criteria along the data path. The tag, also
called the security group tag (SGT), allows the network to enforce the access control policy by enabling
the endpoint device to act upon the SGT to filter traffic.
See the
Cisco Nexus 1000V Security Configuration Guide
for more information on the Cisco TrustSec
feature on Cisco Nexus 1000V.
Cisco TrustSec Troubleshooting Commands
This section contains the following topics:
•
•
Host Logging Commands, page 27-2
•