Cisco ASA Series Configuration Manual page 105

Firewall cli, asa services module, and the adaptive security virtual appliance
Hide thumbs Also See for ASA Series:
Table of Contents

Advertisement

Chapter 6
ASA and Cisco TrustSec
Table 6-3
Ingress Traffic
Interface Configuration
The cts manual command and the
policy static sgt sgt_number command
are both issued.
The cts manual command and the
policy static sgt sgt_number trusted
command are both issued.
If there is no matched IP-SGT mapping from the IP-SGT Manager, then a reserved SGT value of "0x0"
Note
for "Unknown" is used.
The following table describes the expected behavior for egress traffic when configuring this feature.
Table 6-4
Egress Traffic
Interface Configuration
No command is issued.
The cts manual command is issued.
The cts manual command and the propagate sgt command are both issued.
The cts manual command and the no propagate sgt command are both issued.
The following table describes the expected behavior for to-the-box and from-the-box traffic when
configuring this feature.
Table 6-5
To-the-box and From-the-box Traffic
Interface Configuration
No command is issued on the ingress interface for to-the-box
traffic.
The cts manual command is issued on the ingress interface
for to-the-box traffic.
The cts manual command is not issued or the cts manual
command and no propagate sgt command are both issued on
the egress interface for from-the-box traffic.
The cts manual command is issued or the cts manual
command and the propagate sgt command are both issued on
the egress interface for from-the-box traffic.
Note
If there is no matched IP-SGT mapping from the IP-SGT Manager, then a reserved SGT value of "0x0"
for "Unknown" is used.
Tagged Packet Received
SGT value is from the policy static sgt
sgt_number command.
SGT value is from the inline SGT in the
packet.
Tagged or Untagged Packet Received
Packet is dropped.
Packet is accepted, but there is no policy enforcement or SGT
propagation.
Untagged packet is sent, but there is no policy enforcement.
The SGT number is from the IP-SGT Manager.
Tagged packet is sent. The SGT number is from the IP-SGT
Manager.
Untagged Packet Received
SGT value is from the policy static sgt
sgt_number command.
SGT value is from the policy static sgt
sgt_number command.
Tagged or Untagged Packet Sent
Untagged
Tagged
Tagged
Untagged
Cisco ASA Series Firewall CLI Configuration Guide
Guidelines for Cisco TrustSec
6-23

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents