Become a Member
On my controllers I have a management port and my data port. I know that the mgnt port needs to be trusted. Does the data port need to trusted also?
That depends. If you move to Untrusted, then you are essentially invoking the firewall of the controller and then things like AAA profiles, roles, and policies come into play.
The global wired AAA profile controls this behavior by the way. Keep in mind that the port AND/OR the VLAN can be set to untrusted on the controller.
If its the main (only) egress port on the controller, yes you want the port trusted (default) or your user table will fill up with all the wired MACs that can be seen from this port. e.g. hundreds of entries pretty quickly.