EasyManuals Logo
Home>Cisco>Network Router>2901

Cisco 2901 User Manual

Cisco 2901
408 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #159 background imageLoading...
Page #159 background image
151
Cisco 3900 Series, Cisco 2900 Series, and Cisco 1900 Series Integrated Services Routers Generation 2 Software Configuration Guide
Chapter Configuring Security Features
SGT over Ethernet Tagging
SGT over Ethernet Tagging
Cisco TrustSec (CTS) is an end-to-end network infrastructure that provides a scalable architecture for
enforcement of role-based access control, identity-aware networking, and data confidentiality that helps
to secure the network and its resources. CTS works by identifying and authenticating each network user
and resource and assigning a 16-bit number called Security Group Tag (SGT). SGT is then propagated
between network hops to allow intermediary devices (switches and routers) to enforce policies based on
the identity tag.
CTS-capable devices have built-in hardware capabilities than can send and receive packets with SGT
embedded in the MAC (L2) layer. This feature is called L2-SGT imposition. This allows Ethernet
interfaces on the device to be enabled for L2-SGT imposition to enable the device to insert an SGT in
the packet that is to be carried to its next- hop Ethernet neighbor. SGT over Ethernet Tagging is a type
of hop-by-hop propagation of SGTs embedded in clear-text (unencrypted) Ethernet packets.
Restrictions for SGT over Ethernet Tagging
SGT over Ethernet Tagging is supported on plain-text Ethernet frames only.
SGT over Ethernet Tagging is supported on on-board Gigabit Ethernet interfaces on the following
Cisco ISR G2 Series routers:
Cisco ISR G2 2951
Cisco ISR G2 3945
Cisco ISR G2 3900 E Series
Cisco ISR G2 1921
ISR G2 1941
ISR G2 2901
ISR G2 2911
ISR G2 2921
Configuring SGT over Ethernet Tagging
Perform these steps to configure SGT over Ethernet Tagging.
SUMMARY STEPS
1. enable
2. configure terminal
3. interface gigabitethernet slot/port
4. cts manual
5. propagate sgt
6. policy static sgt tag [trusted]
7. end

Table of Contents

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Cisco 2901 and is the answer not in the manual?

Cisco 2901 Specifications

General IconGeneral
Operating altitude0 - 3000 m
Non-operating altitude0 - 4570 m
Storage temperature (T-T)-40 - 70 °C
Operating temperature (T-T)0 - 40 °C
Storage relative humidity (H-H)5 - 95 %
Operating relative humidity (H-H)10 - 85 %
Ethernet LANYes
Cabling technology10/100/1000BASE-T(X)
Networking standardsIEEE 802.1Q, IEEE 802.1ag, IEEE 802.3, IEEE 802.3ab, IEEE 802.3af, IEEE 802.3ah
Ethernet LAN data rates10, 100, 1000 Mbit/s
Ethernet interface typeGigabit Ethernet
DHCP client-
Routing protocolsBGP, EIGRP, OSPF
Supported protocolsIPv4, IPv6, IS-IS, IGMPv3, PIM SM, SSM, DVMRP, IPSec, GRE, BVD, MPLS, L2TPv3, PPP, MLPPP, MLFR, HDLC, RS-232, RS-449, X.21, V.35, EIA-530, PPPoE, ATM
USB version2.0
RS-232 ports1
Expansion slots4 x EHWIC 2 x DSP 1 x ISM
Ethernet LAN (RJ-45) ports2
Firewall securityCisco IOS
Input current1.5 A
AC input voltage100 - 240 V
Power source typeAC
AC input frequency47 - 63 Hz
Power consumption (typical)40 W
Product colorBlack
Rack capacity1U
SafetyUL 60950-1, CAN/CSA C22.2 No. 60950-1, EN 60950-1, AS/NZS 60950-1, IEC 60950-1
Flash memory256 MB
Internal memory512 MB
Electromagnetic compatibility47 CFR, ICES-003, EN55022, CISPR22, AS/NZS 3548, VCCI V-3, EN 300-386, EN 61000, EN 55024, CISPR 24EN50082-1
Weight and Dimensions IconWeight and Dimensions
Depth439.4 mm
Width438.2 mm
Height44.5 mm
Weight6100 g

Related product manuals