Skip to content

CTS

Cisco TrustSec (CTS) is a comprehensive security architecture that provides identity-based access control and encrypted communication across the network infrastructure. It uses Security Group Tags (SGTs) to classify and label traffic based on user identity, device type, or security posture, enabling consistent security policy enforcement regardless of network topology or IP addressing. TrustSec integrates authentication, authorization, encryption, and policy enforcement to create a secure network fabric that can adapt to changing security requirements and threat landscapes.

Diagram
NameTypeConstraintMandatoryDefault Value
ctsClass[cts]No

NameTypeConstraintMandatoryDefault Value
authorization_listStringNo
role_based_enforcement_logging_intervalIntegermin: 5, max: 86400No
role_based_enforcement_vlansListInteger[min: 1, max: 4094]No
role_based_permissions_default_acl_nameListStringNo
sgtIntegermin: 2, max: 65519No
sxp_connection_peers_ipv4List[sxp_connection_peers_ipv4]No
sxp_default_passwordStringNo
sxp_default_password_typeChoice0, 6, 7No
sxpBooleantrue, falseNo
sxp_listener_hold_max_timeIntegermin: 1, max: 65534No
sxp_listener_hold_min_timeIntegermin: 1, max: 65534No
sxp_retry_periodIntegermin: 0, max: 64000No
sxp_speaker_hold_timeIntegermin: 1, max: 65534No

sxp_connection_peers_ipv4 (iosxe.devices.configuration.cts)

Section titled “sxp_connection_peers_ipv4 (iosxe.devices.configuration.cts)”
NameTypeConstraintMandatoryDefault Value
ipIPYes
vrfStringNo
connection_modeChoicelocal, peerNo
hold_timeIntegermin: 0, max: 65535No
max_timeIntegermin: 0, max: 65535No
optionChoiceboth, listener, speakerNo
passwordChoicedefault, key-chain, noneNo
source_ipIPNo

iosxe:
devices:
- name: Device1
configuration:
cts:
authorization_list: TRUSTSEC-AUTHZ-LIST