6-23
Cisco ASA Series Firewall CLI Configuration Guide
Chapter 6 ASA and Cisco TrustSec
Guidelines for Cisco TrustSec
Note
If there is no matched IP-SGT mapping from the IP-SGT Manager, then a reserved SGT value of “0x0”
for “Unknown” is used.
The following table describes the expected behavior for egress traffic when configuring this feature.
The following table describes the expected behavior for to-the-box and from-the-box traffic when
configuring this feature.
Note
If there is no matched IP-SGT mapping from the IP-SGT Manager, then a reserved SGT value of “0x0”
for “Unknown” is used.
The
cts manual
command and the
policy static sgt
sgt_number
command
are both issued.
SGT value is from the
policy static sgt
sgt_number
command.
SGT value is from the
policy static sgt
sgt_number
command.
The
cts manual
command and the
policy static sgt
sgt_number
trusted
command are both issued.
SGT value is from the inline SGT in the
packet.
SGT value is from the
policy static sgt
sgt_number
command.
Table 6-3
Ingress Traffic
Interface Configuration
Tagged Packet Received
Untagged Packet Received
Table 6-4
Egress Traffic
Interface Configuration
Tagged or Untagged Packet Sent
No command is issued.
Untagged
The
cts manual
command is issued.
Tagged
The
cts manual
command and the
propagate sgt
command are both issued.
Tagged
The
cts manual
command and the
no
propagate sgt
command are both issued.
Untagged
Table 6-5
To-the-box and From-the-box Traffic
Interface Configuration
Tagged or Untagged Packet Received
No command is issued on the ingress interface for to-the-box
traffic.
Packet is dropped.
The
cts manual
command is issued on the ingress interface
for to-the-box traffic.
Packet is accepted, but there is no policy enforcement or SGT
propagation.
The
cts manual
command is not issued or the
cts manual
command and
no propagate sgt
command are both issued on
the egress interface for from-the-box traffic.
Untagged packet is sent, but there is no policy enforcement.
The SGT number is from the IP-SGT Manager.
The
cts manual
command is issued or the
cts manual
command and the
propagate sgt
command are both issued on
the egress interface for from-the-box traffic.
Tagged packet is sent. The SGT number is from the IP-SGT
Manager.
Содержание ASA 5508-X
Страница 11: ...P A R T 1 Access Control ...
Страница 12: ......
Страница 60: ...4 14 Cisco ASA Series Firewall CLI Configuration Guide Chapter 4 Access Rules History for Access Rules ...
Страница 157: ...P A R T 2 Network Address Translation ...
Страница 158: ......
Страница 204: ...9 46 Cisco ASA Series Firewall CLI Configuration Guide Chapter 9 Network Address Translation NAT History for NAT ...
Страница 232: ...10 28 Cisco ASA Series Firewall CLI Configuration Guide Chapter 10 NAT Examples and Reference DNS and NAT ...
Страница 233: ...P A R T 3 Service Policies and Application Inspection ...
Страница 234: ......
Страница 379: ...P A R T 4 Connection Management and Threat Detection ...
Страница 380: ......
Страница 400: ...16 20 Cisco ASA Series Firewall CLI Configuration Guide Chapter 16 Connection Settings History for Connection Settings ...
Страница 414: ...17 14 Cisco ASA Series Firewall CLI Configuration Guide Chapter 17 Quality of Service History for QoS ...