Cisco Catalyst 9800 Series Wireless Controller Software Configuration Guide, Cisco IOS XE 26.x

PDF

Cisco Catalyst 9800 Series Wireless Controller Software Configuration Guide, Cisco IOS XE 26.x

TrustSec IP-SGT High Availability binding

Want to summarize with AI?

Log in

Introduces TrustSec IP-to-SGT High Availability binding, highlighting how it synchronizes IP-to-SGT bindings between active and standby devices, preserves bindings during SSO, and ensures consistent SGACL enforcement for uninterrupted policy application during failover events.


TrustSec IP-to-SGT binding High Availability is a redundancy capability that

  • synchronizes supported IP-to-SGT bindings between the active and standby devices

  • preserves binding information during a Stateful Switchover (SSO), and

  • helps maintain consistent Security Group Access Control List (SGACL) enforcement after the switchover.

An IP-to-SGT binding associates an IP address with a Security Group Tag (SGT). TrustSec uses this association to classify traffic and apply the appropriate security policy.

Without binding synchronization, a new active device may need to re-establish connections and relearn bindings after a switchover. Policy enforcement can be delayed while this process occurs. High-availability support makes the required binding information available on the standby device before it assumes the active role.

The list of source-bindings supported for binding synchronization in Cisco TrustSec are:

  • Local source: IP-SGT binding received through authentication of hosts, learned through Endpoint Policy Manager (EPM) and device tracking.

  • SXP source: IP-SGT binding received through Security Group Tag Exchange Protocol (SXP) peers.

  • VLAN source: IP-SGT binding received through VLAN-to-SGT mapping.

  • L3IF binding: Binding received through Layer 3 Logical Interface (L3IF) learning.


Verify TrustSec IP-SGT High Availability binding support

As part of the system’s synchronization functionality, active bindings are automatically propagated to and displayed on the standby unit to ensure High Availability and consistent policy enforcement across the cluster.

To view all the mappings of IP address to Security Group Tag, use this command:

Device# show cts role-based sgt-map all
Active IPv4-SGT Bindings Information

IP Address              SGT     Source
============================================
1.1.1.1                 3       CLI
20.1.1.1                1010    SXP
20.1.1.2                1001    SXP
22.1.1.1                2       SXP
33.1.1.2                2       SXP
55.1.1.1                3       SXP
200.1.1.1               9001    SXP
200.1.1.2               9002    SXP
200.1.1.3               9003    SXP
200.1.1.4               9004    SXP
200.1.1.5               9005    SXP
200.1.1.6               9006    SXP
200.1.1.7               9007    SXP
200.1.1.8               9008    SXP
200.1.1.9               9009    SXP
200.1.1.10              9010    SXP
200.1.1.11              9011    SXP
200.1.1.12              9012    SXP
200.1.1.13              9013    SXP
200.1.1.14              9014    SXP
200.1.1.15              9015    SXP
200.1.1.16              9016    SXP
200.1.1.17              9017    SXP
200.1.1.18              9018    SXP
200.1.1.19              9019    SXP
200.1.1.20              9020    SXP
200.1.1.21              9021    SXP
200.1.1.22              9022    SXP
200.1.1.23              9023    SXP
200.1.1.24              9024    SXP
200.1.1.25              9025    SXP
200.1.1.26              9026    SXP
200.1.1.27              9027    SXP
200.1.1.28              9028    SXP
200.1.1.29              9029    SXP
200.1.1.30              9030    SXP

IP-SGT Active Bindings Summary
============================================
Total number of CLI      bindings = 1
Total number of SXP      bindings = 35
Total number of active   bindings = 36

Active IPv6-SGT Bindings Information

IP Address                                  SGT     Source
================================================================

To view the standby mappings, use this command:

standby-device# show cts role-based sgt-map all 
Active IPv4-SGT Bindings Information

IP Address              SGT     Source
============================================
1.1.1.1                 3       CLI
20.1.1.1                1010    SXP
20.1.1.2                1001    SXP
22.1.1.1                2       SXP
33.1.1.2                2       SXP
55.1.1.1                3       SXP
200.1.1.1               9001    SXP
200.1.1.2               9002    SXP
200.1.1.3               9003    SXP
200.1.1.4               9004    SXP
200.1.1.5               9005    SXP
200.1.1.6               9006    SXP
200.1.1.7               9007    SXP
200.1.1.8               9008    SXP
200.1.1.9               9009    SXP
200.1.1.10              9010    SXP
200.1.1.11              9011    SXP
200.1.1.12              9012    SXP
200.1.1.13              9013    SXP
200.1.1.14              9014    SXP
200.1.1.15              9015    SXP
200.1.1.16              9016    SXP
200.1.1.17              9017    SXP
200.1.1.18              9018    SXP
200.1.1.19              9019    SXP
200.1.1.20              9020    SXP
200.1.1.21              9021    SXP
200.1.1.22              9022    SXP
200.1.1.23              9023    SXP
200.1.1.24              9024    SXP
200.1.1.25              9025    SXP
200.1.1.26              9026    SXP
200.1.1.27              9027    SXP
200.1.1.28              9028    SXP
200.1.1.29              9029    SXP
200.1.1.30              9030    SXP

IP-SGT Active Bindings Summary
============================================
Total number of CLI      bindings = 1
Total number of SXP      bindings = 35
Total number of active   bindings = 36

Active IPv6-SGT Bindings Information

IP Address                                  SGT     Source
================================================================