View Cart
0 Items | Total: US$0.00
Welcome,      Register

You are here

SEC0219 - ISE 2.0 TrustSec - FlexVPN and ZBFW (Part 1)

Average: 5 (2 votes)
Difficulty Level: 
Lab Document: 
<Please login to see the content>
Video Download: 
Title: SEC0219 - Video Download $14.00
Purchase SEC0219 - Video Download $14.00
The video attempts to implement SGT propagation across a WAN over FlexVPN. We will demonstrate capability of Cisco router in participating Cisco TrustSec including joining SGT trust domain, Network Device Authorization, SGT propagation, and enforcement. We will configure ZBFW to utilize source SGT in conjunction with ACL to restrict network access.
Part 1 of this video covers adding router to TrustSec domain and enable SGT over FlexVPN
  • SGT Manual Trust
  • SGT Over FlexVPN
  • Network Device Authorization (Router)
  • Zone-Based Firewall (ZBFW)

About Author

Metha Cheiwanichakorn, CCIE#23585 (RS, Sec, SP), is a Cisco networking enthusiast with years of experience in the industry. He is currently working as a consulting engineer for a Cisco partner. As a founder of and an instructor at, Metha enjoys learning and challenges himself with new Cisco technologies.


Hello. , in this link it is written that SGT tagging over VPN is not supported with FlexVPN. But in you videos you are using FlexVPN. May you explain?

The article was from 2011. May be it wasn't supported back then. Below is another Cisco doc that tell you how to do it so clearly it is supported.

Thank you for clarification. One more question: I really admire your job and your videos really helped me in practice and exam preparation. I wonder whether you have plans like creating video series for WSA,ESA,CWS for preparing SITCS exam.

We do not at this time.