22.05.2017 Views

nx.os.and.cisco.nexus.switching.2nd.edition.1587143046

Nexus Switching 2nd Edition

Nexus Switching 2nd Edition

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

NX7K-SGA#<br />

The next thing to do is to create Security Group Access Control Lists (SGACL) that will be<br />

used to create security policy.<br />

Policy Component: SGACL Creation<br />

1. Go to Policy >Policy Elements >Results >Security Group Access > Security<br />

Group ACLs.<br />

2. Enter WebServers for the name <strong>and</strong> then the SGACL to permit http, https, dns, icmp<br />

(ping), <strong>and</strong> deny RDP traffic (3389), as demonstrated in Example 5-35.<br />

Example 5-35. Policy Created for Web <strong>and</strong> Database Servers<br />

WebServers<br />

permit tcp dst eq 80<br />

permit tcp dst eq 443<br />

permit udp dst eq 53<br />

permit icmp<br />

deny tcp dst eq 3389<br />

Database Servers<br />

permit tcp dst eq 1433<br />

3. Click Push to deploy the security group ACLs.<br />

Now that you have SGT <strong>and</strong> SGACLs defined, you need to construct the Egress policy:<br />

1. Go to Policy > Security Group Access > Egress Policy.<br />

2. Click Add Security Group ACL Mapping.<br />

3. Select Source Security Group as IT_Servers <strong>and</strong> Destination Security Group as<br />

Finance_Servers.<br />

For the Assigned Security Group ACLs, you need to enforce the SGACL policy created on<br />

ISE, as demonstrated in Example 5-36.<br />

Example 5-36. Enforcing the SGACL Policy on the Nexus 7000<br />

Click here to view code image<br />

NX7K-SGA# conf t<br />

Enter configuration comm<strong>and</strong>s, one per line. End with<br />

CNTL/Z.<br />

NX7K-SGA(config)# cts role-based enforcement<br />

NX7K-SGA(config)# cts role-based counters enable<br />

Note: Clearing previously collected counters...

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!