Outlines Cisco TrustSec architecture, including user and device identity, scalable access controls, data confidentiality, and enforcement using Cisco ISE and SGACLs. Highlights SGACL and SGT inline tagging features, supported platforms, HA policy for FlexConnect, and commands for managing environment data.
A Cisco TrustSec solution is a network security architecture that
-
strongly identifies users, hosts, and network devices within the network
-
provides topology-independent and scalable access controls by classifying data traffic based on user or device roles, and
-
ensures data confidentiality and integrity by establishing trust among authenticated peers and encrypting network links.
The key component of Cisco TrustSec is the Cisco Identity Services Engine (ISE). Cisco ISE can provision switches with TrustSec Identities and Security Group ACLs (SGACLs). SGACLs may be configured manually on the switch.
Before changing CTS server to a new one, manually clear the CTS environment data using the clear cts environment-data command. Running the show cts environment-data command will return updated data.
Feature History
| Feature Name |
Release |
Description |
|---|---|---|
| Trustsec policy HA support for FlexConnect mode APs |
Cisco IOS XE 17.18.2 |
The feature ensures that CTS SGACL enforcement remains available and consistent during HA events such as Stateful Switchover (SSO) between wireless controllers. This provides uninterrupted security policy enforcement on Flex mode APs even during controller failover or redundancy events. |
| TrustSec support for Cisco Catalyst IW6300 Heavy Duty Series and 6300 Series Embedded Services APs |
Cisco IOS XE 17.8.1 |
Enable and configure Cisco TrustSec Security Group ACL (SGACL) in FlexConnect and Flex+Bridge mode. SGACL enforcement on the controller is available for local and Bridge mode. Inline tagging and SXP are supported only in FlexConnect. |
| Support for SGT Inline Tagging Over Port-Channel Uplink |
Cisco IOS XE 17.3.5a |
SGT inline tagging over port-channel uplink is supported for Cisco Catalyst 9800-L, 9800-40, and 9800-80 Wireless Controllers. If you downgrade to releases that do not support SGT inline tagging over port-channel, the port-channel may be suspended. |