Cisco Catalyst 9800 Series Wireless Controller Software Configuration Guide, Cisco IOS XE 26.1.x

PDF

Cisco Catalyst 9800 Series Wireless Controller Software Configuration Guide, Cisco IOS XE 26.1.x

Cisco TrustSec - ISE communication over IPv6

Want to summarize with AI?

Log in

Outlines Cisco TrustSec’s IPv6 capabilities, including policy-centric security management, RADIUS-based ISE communication, enforcement of security and identity policies, SGACL provisioning, and IPv6 address support to enable secure, scalable network modernization.


IPv6 transition for Cisco TrustSec

Cisco TrustSec is a security framework that

  • implements business security needs through policy-centric management,

  • provides integrated security features such as segmentation, identity management, access control, and data protection,

  • facilitates communication between network devices and policy servers using the RADIUS protocol over IPv6.

This framework allows organizations to enforce security policies effectively across their networks, adapting to the growing demand for IPv6 addressing.

The transition to IPv6 for Cisco TrustSec involves:

  • Supporting IPv6 addresses for end-user policy enforcement and identity management.

  • Enabling communication with the Identity Services Engine (ISE) for provisioning Security Group ACL (SGACL) policies over IPv6.

  • Maintaining a list of IPv6 addresses and load balancing them during policy download.

This transition is essential for organizations looking to modernize their network security infrastructure and ensure compatibility with future technologies.


Limitations of IPv4

The limitations of IPv4 addressing include:

  • Limited address space: Due to its 32-bit addressing system, IPv4 is limited to approximately 4.3 billion unique addresses, which is insufficient for the increasing number of internet-connected devices.

  • Dependency on NAT: It requires Network Address Translation (NAT) to extend the address space, which complicates network design and can hinder connectivity.

  • Lack of native support: It lacks native support for modern features such as end-to-end encryption and mobility.

  • Routing inefficiencies: It creates inefficiencies in routing tables, leading to increased processing overhead for routers.


Configure TrustSec SXP with IPv6 (GUI)

Enable IPv6 communication for Cisco TrustSec to enhance security policy management.

Use this task to configure RADIUS server settings to support IPv6 addresses for TrustSec operations.

Before you begin

  • Ensure that your network devices are capable of supporting IPv6.

  • Verify that the Identity Services Engine (ISE) is configured to accept IPv6 connections.

Procedure

1.

Choose Configuration > Security > Trustsec.

2.

On the Trustsec page, click the SXP tab. The Peer Connections section is displayed.

3.

In the SXP Parameters section, enable the SXP Status.

4.

Specify the Default Source IPv6 address and the default password.

5.

In the Peer Connections section, click Add.

6.

On the Add Peer Connection page, configure these parameters:

  1. From the Mode of Local Device drop-down list, select either listener, speaker, or both.

  2. From the IP Type drop-down list select IPv6.

  3. Enter the Peer IP and the Source IP addresses.

  4. Enter the Password.

  5. Click Apply to Device.

7.

Click Apply.

IPv6 is now enabled for TrustSec operations and RADIUS communications.


Configure TrustSec SXP with IPv6

Enable IPv6 communication for Cisco TrustSec to enhance security policy management.

Use this task to configure RADIUS server settings to support IPv6 addresses for TrustSec operations.

Before you begin

  • Ensure that your network devices are capable of supporting IPv6.

  • Verify that the Identity Services Engine (ISE) is configured to accept IPv6 connections.

Procedure

1.

Enter global configuration mode.

Example:

Device# configure terminal
2.

Configure CTS SXP with IPv6 address.

Example:

Device(config)# cts sxp default source-ipv6 <X:X:X:X::X source ipv6 address>
3.

Complete these steps to configure the CTS SXP connection parameters.

  1. Configure CTS SXP connection peer IP address. You can configure either IPv4 or IPv6 IP address of the peer.

  2. Set the password option. You can choose a default password, or use a configured key-chain for authentication, or opt for no password.

  3. Set the connection role as either local or peer and then set an SXP mode.

  4. Specify the VRF. If the SXP connection should be in a specific VRF, include the VRF name.

    Example:

    Device(config)# cts sxp connection peer {A.B.C.D | X:X:X:X::X} 
                                                password {default | key-chain | none} 
                                                mode {local | peer} {both | listener hold-time | speaker hold-time}
                                                vrf <vrf-name>
    Device(config)# cts sxp connection peer 2001:db8::1 password default mode local both vrf mgmt-vrf
4.

Configure CTS SXP node ID.

Example:

Device(config)# cts sxp node-id {interface | ipv4 | ipv6}
Note
The node ID is a 32-bit value. When enabling SXP over IPv6, a node ID must be explicitly configured; an IPv6 address cannot be used as the node ID.
5.

Configure CTS SXP export-import VRF group.

Example:

Device(config)# cts sxp export-import-group <group-name> 
6.

Configure CTS SXP export-import VRF group.

Example:

Device(config)# cts sxp export-import-group <group-name> 
TrustSec SXP is successfully configured to support IPv6 communication, enabling enhanced security policy management and seamless connectivity between devices using IPv6 addresses.

Verify Cisco TrustSec PAC over IPv6 RADIUS

To verify Cisco TrustSec PAC over IPv6 RADIUS, use these show commands:

To view the A-ID and PAC information for PACs in the key store, use this command:

Device# show cts pacs
AID: 60DABBF8AD435A7B63900EE07E68D2FD
PAC-Info:
  PAC-type = Cisco Trustsec
  AID: 60DABBF8AD435A7B63900EE07E68D2FD
  I-ID: ha_senth_cat9k
  A-ID-Info: Identity Services Engine
  Credential Lifetime: 16:17:20 UTC Mon Feb 24 2025
PAC-Opaque: 000200B8000300010004001060DABBF8AD435A7B63900EE07E68D2FD0006009C00030100292A512B0798BEBB4F096D639A67B49000000013673F6EE400093A80F9289E9324A137E3CA2C0583927813B345C78350FB644DDE545A428E9431497385FB172C075575F94E327555AA4BAF010E172E3B6304BB59E32CA849E335FC758B5AFED056B19860684E092486AF938DA5453E3C4EF5F6E740B9500BA4EEF46602D21EDBDDE01C4549514B35DC11F1CF81B6A2B517E2BFF1A84A705E
Refresh timer is set for 12w4d

To view the queue for provisioning requests, use this command:

Device# show ctw provisioning queue
Server: 20XX:420:54XX:4::400:11, Type: Radius, Provisioned: YES
AID: 3ec5d7e02bde9fd04c453918a5e2d3b4

To view the Cisco TrustSec environment data, use this command:

Device# show cts environment-data
CTS Environment Data
====================
Current state = COMPLETE
Last status = Successful
Service Info Table:
Local Device SGT:
  SGT tag = 2-48:TrustSec_Devices
Server List Info:
Installed list: CTSServerList1-0003, 3 server(s):
 *Server: 2001:420:54FF:4::400:11, port 1812, A-ID 1695AF86D38B22DC7C9500408E2DD35D
          Status = DEAD
          auto-test = TRUE, keywrap-enable = FALSE, idle-time = 60 mins, deadtime = 20 secs
 *Server: 2001:420:54FF:4::400:12, port 1812, A-ID 1695AF86D38B22DC7C9500408E2DD35D
          Status = ALIVE
          auto-test = TRUE, keywrap-enable = FALSE, idle-time = 60 mins, deadtime = 20 secs
 *Server: 2001:420:54FF:4::400:13, port 1812, A-ID 1695AF86D38B22DC7C9500408E2DD35D
          Status = DEAD
          auto-test = TRUE, keywrap-enable = FALSE, idle-time = 60 mins, deadtime = 20 secs
Security Group Name Table:
    0-48:Unknown
    2-48:TrustSec_Devices
    3-62:Network_Services
    4-56:Employees
    5-48:Contractors
    6-49:Guests
    7-48:Production_Users
    8-49:Developers
    9-49:Auditors
    10-48:Point_of_Sale_Systems
    11-48:Production_Servers
    12-0177:Development_Servers
    13-48:Test_Servers
    14-56:PCI_Servers
    15-48:BYOD
    16-01:sgt_101
Environment Data Lifetime = 86400 secs 
Last update time = 05:26:38 UTC Tue Jul 1 2025
Env-data expires in   0:23:52:36 (dd:hr:mm:sec)
Env-data refreshes in 0:23:52:36 (dd:hr:mm:sec)
Cache data applied           = NONE
State Machine is running
Retry_timer (60 secs) is not running