Purpose and Functionality #
The Cisco Service Gateway (SG) acts as the bridge between the customer’s network and the cloud service, facilitating seamless integration and secure communication. Deployed as a Cisco router running IOS-XE, the SG is positioned within the network traffic flow to enable the cloud service on existing LAN and WLAN infrastructures from any vendor.
Key Features #
- Secure Communication:
- Communication between the cloud service and the SG is secured with an encrypted tunnel using FlexVPN.
- Supports redundancy through hot standby for failover or load balancing for optimized performance.
- Integration:
- Positioned between the guest network (inside interface) and the internet (outside interface).
- Can be deployed behind a customer firewall for additional security.
- Vendor Compatibility:
- Enables service on existing LAN-based and Wireless LAN-based networks from any vendor.
- Scalability:
- Customers can choose an appropriate Cisco router model as the SG, tailored to their performance requirements and business needs.
Advanced Capabilities #
- Policy-Based Routing (PBR):
Ensures efficient traffic handling based on predefined policies. - Dynamic Segmentation:
Utilizes SGT/SXP tunnels with SGT-to-IP mapping for secure and dynamic network segmentation. - Logical Independence:
Each SG instance operates within its own isolated framework using VRF (Virtual Routing and Forwarding), ensuring separation and operational independence.

ServiceGateway Router Support Matrix #
The table below lists the Cisco router series that are verified and fully compatible with the SignIn ServiceGateway integration. The specified license levels are required to enable the features utilized by the integration.
| Router Series | Required License | Feature Utilization | Support Status |
|---|---|---|---|
| Cisco ISR 1100 Series | Security (SEC/K9) + AppX | Cisco TrustSec (CTS), PBR/ePBR, NBAR, IPSec (FlexVPN), NAT, BGP, VRF | ✅ Supported |
| Cisco ISR 4400 Series | Security (SEC/K9) + AppX | Cisco TrustSec (CTS), PBR/ePBR, NBAR, IPSec (FlexVPN), NAT, BGP, VRF | ✅ Supported |
| Cisco Catalyst 8100 Series | DNA Essentials | Cisco TrustSec (CTS), PBR/ePBR, NBAR, IPSec (FlexVPN), NAT, BGP, VRF | ✅ Supported |
| Cisco Catalyst 8200 Series | DNA Essentials | Cisco TrustSec (CTS), PBR/ePBR, NBAR, IPSec (FlexVPN), NAT, BGP, VRF | ✅ Supported |
| Cisco Catalyst 8300 Series | DNA Essentials | Cisco TrustSec (CTS), PBR/ePBR, NBAR, IPSec (FlexVPN), NAT, BGP, VRF | ✅ Supported |
| Cisco Catalyst 8400 Series | DNA Essentials | Cisco TrustSec (CTS), PBR/ePBR, NBAR, IPSec (FlexVPN), NAT, BGP, VRF | ✅ Supported |
| Cisco Catalyst 8500 Series | DNA Essentials | Cisco TrustSec (CTS), PBR/ePBR, NBAR, IPSec (FlexVPN), NAT, BGP, VRF | ✅ Supported |
Note #
-
Require Cisco IOS XE 17.3.8a or later.