Validating SGT Inline with Netflow and Embedded Packet Capture
In the last article, Learning TrustSec, An Introduction to Inline Tagging, we took a quick look at manual configuration of SGT Inline Tagging in a manual configuration. We also performed some validation with show commands and proved the operation by enabling enforcement.
In today’s article, we will perform slightly deeper validation of the inline imposition itself. For this process, we will use Netflow and Embedded Packet Capture. I happen to know that there is already EIGRP traversing the link that will help produce some output. Let’s just jump right in with a very basic Netflow configuration.
Netflow Configuration
//you could additionally configure and exporter //if there is a proper netflow collector flow record my_record_output match flow cts source group-tag match flow cts destination group-tag match ipv4 source address match ipv4 destination address match ipv4 protocol match transport source-port match transport destination-port flow monitor my_monitor_output record my_record_output ! interface GigabitEthernet1/0/1 description trunk to c9kSW2 switchport mode trunk ip flow monitor my_monitor_output output cts manual policy static sgt 100 trusted
Verification Using Netflow
c9kSW1#show flow monitor my_monitor_output cache
Cache type: Normal (Platform cache)
Cache size: 10000
Current entries: 1
Flows added: 9
Flows aged: 8
- Active timeout ( 1800 secs) 2
- Continue reading
The managed security service provider tested Netskope’s and McAfee Skyhigh’s technology before choosing Bitglass.
CRI-O was launched as a lighter alternative to using Docker as the runtime for Kubernetes.
Nimble platforms now support Storage Class Memory (SCM) and NVMe for super-fast, low-latency flash storage.
SpaceTime’s CEO Rob Schilling, a former general manager at SAP, will join Nokia’s IoT unit.
The service provider is using a single platform from Nokia's Nuage to enable end-to-end automation between its WAN overlay service and its data center overlay service.