Introduces TrustSec IP-to-SGT High Availability binding, highlighting how it synchronizes IP-to-SGT bindings between active and standby devices, preserves bindings during SSO, and ensures consistent SGACL enforcement for uninterrupted policy application during failover events.
TrustSec IP-to-SGT binding High Availability is a redundancy capability that
-
synchronizes supported IP-to-SGT bindings between the active and standby devices
-
preserves binding information during a Stateful Switchover (SSO), and
-
helps maintain consistent Security Group Access Control List (SGACL) enforcement after the switchover.
An IP-to-SGT binding associates an IP address with a Security Group Tag (SGT). TrustSec uses this association to classify traffic and apply the appropriate security policy.
Without binding synchronization, a new active device may need to re-establish connections and relearn bindings after a switchover. Policy enforcement can be delayed while this process occurs. High-availability support makes the required binding information available on the standby device before it assumes the active role.
The list of source-bindings supported for binding synchronization in Cisco TrustSec are:
-
Local source: IP-SGT binding received through authentication of hosts, learned through Endpoint Policy Manager (EPM) and device tracking.
-
SXP source: IP-SGT binding received through Security Group Tag Exchange Protocol (SXP) peers.
-
VLAN source: IP-SGT binding received through VLAN-to-SGT mapping.
-
L3IF binding: Binding received through Layer 3 Logical Interface (L3IF) learning.