show cts role-based policy
To display the global Cisco TrustSec security group access control list (SGACL) policies, use the show cts
role-based policy command.
show cts role-based policy [sgt{sgt-value| any| unknown}| dgt{dgt-value| any| unknown}| configured|
downloaded| monitored]
Syntax Description
Specifies the source security group tag (SGT).sgt
Source SGT value. The range is from 0 to 65535.
sgt-value
Specifies any SGT or DGT.any
Specifies an unknown SGT or DGT.unknown
Specifies the destination security group tag (DGT).dgt
Destination SGT value. The range is from 0 to 65535.
dgt-value
Displays the SGACLs configured by using CLI.configured
Displays the SGACLs downloaded from ISE.downloaded
Displays the monitored SGACLs.monitored
Command Default
None
Command Modes
Any configuration mode.
Command History
ModificationRelease
The sgt, dgt, configured, downloaded, and monitored keywords were added.
Additionally, the command output was updated.
8.0(1)
This command was introduced.4.0(1)
Usage Guidelines
To use this command, you must enable the Cisco TrustSec feature using the feature cts command.
This command requires the Advanced Services license.
Cisco Nexus 7000 Series Security Command Reference
749
Show Commands
show cts role-based policy