Loading...
Loading...
In SD-Access and TrustSec-enabled environments, Cisco Catalyst Center (formerly DNA Center) automatically provisions Virtual Networks (VNs) and corresponding SXP domains in ISE via API. Administrators often expect these automatically generated domains to be available for static IP-SGT assignments to maintain consistency across the fabric. Without documentation clarifying this limitation, users spend significant time troubleshooting "missing" domains in the UI, leading to increased support cases and deployment delays.
When navigating to Work Centers > TrustSec > Components > IP SGT Static Mapping and attempting to add or edit a mapping: The "SXP Domain" dropdown menu does not list domains that were created automatically by API. Only the "Default" domain and any domains created manually within the ISE GUI are visible. The administrator is unable to pin a static IP-SGT binding to a specific SXP Domain if it was provisioned via the /api/v1/trustsec/virtualnetwork API call.
Manual Domain Creation: Manually create a new SXP Domain under Work Centers > TrustSec > SXP > SGT Domains with a unique name. This manually created domain will be selectable for static mappings.
Cisco Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.