300-715 · Question #273
An organization has a SGACL locally configured on a switch port, but when a user in the Executives group connects to the network, they receive a different level of network access than expected. When C
The correct answer is D. The policies are merged, but dynamically downloaded policies receive priority.. When both local and dynamically downloaded Security Group Access Control Lists (SGACLs) exist for a user, the switch merges them, with the dynamically downloaded policies from Cisco ISE taking precedence.
Question
An organization has a SGACL locally configured on a switch port, but when a user in the Executives group connects to the network, they receive a different level of network access than expected. When Cisco ISE pushes SGACLs to the switch after the authorization phase, how does the switch decide which access to grant the user?
Options
- ADynamically downloaded policies override local policies in all cases.
- BLocal policies override dynamically downloaded policies in all cases.
- CThe policies are merged, but local policies receive priority.
- DThe policies are merged, but dynamically downloaded policies receive priority.
How the community answered
(21 responses)- A5% (1)
- B10% (2)
- D86% (18)
Why each option
When both local and dynamically downloaded Security Group Access Control Lists (SGACLs) exist for a user, the switch merges them, with the dynamically downloaded policies from Cisco ISE taking precedence.
While dynamically downloaded policies do override local policies, the term 'in all cases' is too absolute; it's more accurate to say they receive priority in a merge scenario.
This is incorrect; dynamically downloaded policies from ISE typically take precedence over local configurations.
While the policies are merged, dynamically downloaded policies receive priority, not local policies.
In Cisco TrustSec, when a switch has both a locally configured SGACL on a port and receives a dynamically downloaded SGACL from Cisco ISE during authorization, the switch merges these policies. However, dynamically downloaded policies (from ISE) are given priority over locally configured policies for the endpoint.
Concept tested: Cisco TrustSec SGACL policy precedence
Source: https://www.cisco.com/c/en/us/td/docs/switches/lan/trustsec/configuration/guide/trustsec-guide/sg_acls.html
Topics
Community Discussion
No community discussion yet for this question.