cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
990
Views
0
Helpful
2
Replies

IP to SGT Mapping Question

edmcnich
Cisco Employee
Cisco Employee

I have a customer that has 802.1x to ISE configured on his Meraki MS switches. They also have SXP configured between ISE and an upstream ISR router. They would like to configure SGACLs on the ISRs using the dynamically configured SGTs assigned in ISE, and publish these SGTs to the ISR router (SXP Listerner).

I guess the question is, can ISE create dynamic IP to SGT mapping using 802.1x from Meraki (not SXP speaker, because Meraki doesn't support it), and publish to an ISR via SXP?

2 Accepted Solutions

Accepted Solutions

umahar
Cisco Employee
Cisco Employee

In general this is supported, havn't actually integrated with Meraki.

If ISE is the one tagging 802.1x endpoints on Meraki then this should be possible.

Be sure to enable the below setting. This should populate the IP-SGT bindings on ISE with dynamic tags for radius sessions.

 

d54efb4b-e990-4fff-9b4b-dc7f35e4c5f5.png

View solution in original post

gbekmezi-DD
Level 5
Level 5
This should work. You assign the SGT in the authorization result and it should get added to the internal mapping in ISE, which should then get propagated to SXP clients.


View solution in original post

2 Replies 2

umahar
Cisco Employee
Cisco Employee

In general this is supported, havn't actually integrated with Meraki.

If ISE is the one tagging 802.1x endpoints on Meraki then this should be possible.

Be sure to enable the below setting. This should populate the IP-SGT bindings on ISE with dynamic tags for radius sessions.

 

d54efb4b-e990-4fff-9b4b-dc7f35e4c5f5.png

gbekmezi-DD
Level 5
Level 5
This should work. You assign the SGT in the authorization result and it should get added to the internal mapping in ISE, which should then get propagated to SXP clients.