300-715 · Question #248
An engineer is configuring static SGT classification. Which configuration should be used when authentication is disabled and third-party switches are in use?
The correct answer is B. IP Address to SGT mapping. When authentication is disabled (no 802.1X or MAB) and third-party (non-Cisco TrustSec-capable) switches are in use, IP Address to SGT mapping is the correct static SGT classification method. VLAN-to-SGT and L3IF-to-SGT mappings require TrustSec-capable Cisco switches that can…
Question
An engineer is configuring static SGT classification. Which configuration should be used when authentication is disabled and third-party switches are in use?
Options
- AVLAN to SGT mapping
- BIP Address to SGT mapping
- CL3IF to SGT mapping
- DSubnet to SGT mapping
How the community answered
(34 responses)- A3% (1)
- B85% (29)
- C9% (3)
- D3% (1)
Explanation
When authentication is disabled (no 802.1X or MAB) and third-party (non-Cisco TrustSec-capable) switches are in use, IP Address to SGT mapping is the correct static SGT classification method. VLAN-to-SGT and L3IF-to-SGT mappings require TrustSec-capable Cisco switches that can enforce inline tagging. Subnet-to-SGT is a broader form of IP mapping but IP Address-to-SGT is the specific per-host static method that works independently of authentication state and switch TrustSec capability, making it the only viable option in this environment.
Topics
Community Discussion
No community discussion yet for this question.