TrustSec (on supported models)
E665677
TrustSec (on supported models) is Cisco’s software-defined segmentation and access control technology that uses security group tags to enforce scalable, identity-based network security policies on supported Catalyst switches.
Observed surface forms (1)
| Surface form | Occurrences |
|---|---|
| Cisco TrustSec | 1 |
Statements (45)
| Predicate | Object |
|---|---|
| instanceOf |
Cisco TrustSec deployment
ⓘ
network security technology ⓘ |
| appliesTo | data plane traffic ⓘ |
| benefit |
consistent access control across supported Catalyst switches
ⓘ
faster policy changes with minimal network reconfiguration ⓘ scalable policy enforcement independent of IP addressing ⓘ |
| category |
access control
ⓘ
enterprise network security ⓘ network segmentation ⓘ |
| configuredWith |
Cisco DNA Center (policy integration)
NERFINISHED
ⓘ
Cisco IOS CLI NERFINISHED ⓘ |
| controls | network access ⓘ |
| designedFor | Cisco Catalyst switches NERFINISHED ⓘ |
| developer | Cisco Systems NERFINISHED ⓘ |
| enforces |
identity-based network security policies
ⓘ
role-based access policies ⓘ |
| implements |
identity-based access control
ⓘ
software-defined segmentation ⓘ |
| integratesWith |
Cisco ISE
NERFINISHED
ⓘ
Cisco Identity Services Engine NERFINISHED ⓘ |
| partOf | Cisco TrustSec NERFINISHED ⓘ |
| provides |
dynamic access control
ⓘ
group-based policy enforcement ⓘ reduced dependence on IP-based ACLs ⓘ simplified policy management ⓘ |
| reliesOn |
centralized policy definition
ⓘ
identity information from authentication systems ⓘ |
| requires | supported Catalyst switch models ⓘ |
| scopeNote | availability and features depend on specific Catalyst switch models and software versions ⓘ |
| supports |
end-to-end SGT propagation on supported platforms
ⓘ
macro-segmentation ⓘ micro-segmentation ⓘ multi-domain segmentation (campus, WAN, data center) on supported platforms ⓘ policy-based segmentation ⓘ scalable network security policies ⓘ |
| targetEnvironment |
branch networks
ⓘ
campus networks ⓘ enterprise LANs ⓘ |
| uses |
Cisco IOS or IOS XE features
NERFINISHED
ⓘ
SGACLs NERFINISHED ⓘ SGT-based policy enforcement ⓘ Security Group Access Control Lists NERFINISHED ⓘ Security Group Tag propagation ⓘ inline tagging ⓘ security group tags ⓘ |
Referenced by (2)
Full triples — surface form annotated when it differs from this entity's canonical label.
subject surface form:
Cisco NX-OS
this entity surface form:
Cisco TrustSec