Autotransition from custom SGTs to ISE SGTs
When you create rules based on custom Security Group Tags (SGTs) and subsequently configure ISE or ISE-PIC as the identity source, the system:
-
Disables Security Group Tag options in the object manager. Although the system retains existing SGT objects, you cannot modify them or add new ones.
-
The system keeps your existing rules with custom SGT conditions, but these rules do not match traffic. You also cannot add more custom SGT criteria to your existing rules or create new rules with custom SGT conditions.
If you configure ISE, Cisco recommends that you delete or disable existing rules with custom SGT conditions. Instead, use ISE attribute conditions to match traffic with SGT attributes.