Description
Cisco TrustSec Feature
An SGT is a 16-bit single label indicating the security
classification of a source in the TrustSec domain. It
is appended to an Ethernet frame or an IP packet.
Security Group Tag (SGT)
Security Group Tag Exchange Protocol (SXP). With
SXP, devices that are not TrustSec-hardware-capable
can receive SGT attributes for authenticated users
and devices from the Cisco Identity Services Engine
(ISE) or the Cisco Secure Access Control System
(ACS). The devices can then forward a
sourceIP-to-SGT binding to a
TrustSec-hardware-capable device will tag the source
traffic for SGACL enforcement.
SGT Exchange Protocol (SXP)
Feature Information for Cisco TrustSec
This table lists the features in this module and provides links to specific configuration information.
Table 37: Feature Information for Cisco TrustSec
Feature
Information
Releases
Feature Name
SXP is introduced
on the Catalyst
2960-X switch.
15.0(2)EX
Cisco TrustSec
SXP is introduced
on the Catalyst
2960-XR switch.
15.0(2)EX1
Catalyst 2960-XR Switch Security Configuration Guide, Cisco IOS Release 15.0(2)EX1
OL-29434-01
375
Configuring Cisco TrustSec
Feature Information for Cisco TrustSec