264
Configuring SGT Exchange Protocol over TCP (SXP) and Layer 3 Transport
Configuring Cisco TrustSec SXP
Enabling Cisco TrustSec SXP
You must enable Cisco TrustSec SXP before you can configure peer connections. To enable Cisco TrustSec SXP, perform
this task:
Configuring an SXP Peer Connection
You must configure the SXP peer connection on both of the devices. One device is the speaker and the other is the
listener. When using password protection, make sure to use the same password on both ends.
Note: If a default SXP source IP address is not configured and you do not configure an SXP source address in the
connection, the Cisco TrustSec software derives the SXP source IP address from existing local IP addresses. The SXP
source address might be different for each TCP connection initiated from the switch.
To configure the SXP peer connection, perform this task:
Command Purpose
1.
Router# configure terminal
Enters global configuration mode.
2.
Router(config)# [no] cts sxp enable
Enables SXP for Cisco TrustSec.
3.
Router(config)# exit
Exits configuration mode.