Create a security group tag object
This task allows you to add a security group tag object to enforce network access policies based on SGT.
You can create security group tag objects only in the global domain. A Control license is required for Classic devices. Any Smart License provides coverage for Smart Licensed devices.
Before you begin
-
Disable ISE or ISE-PIC connections because custom SGT objects cannot be created if either is used as an identity source.
Click , click None, then click Save.
-
See Best practices for ISE/ISE-PIC integration for guidelines for using the identity source.
Follow these steps to create a security group tag object:
Procedure
Step 1 | Click . |
Step 2 | Click . |
Step 3 | Click Add Security Group Tag. |
Step 4 | Enter a Name. |
Step 5 | Optionally, enter a Description. |
Step 6 | In the Tag field, enter a single SGT. |
Step 7 | Click Save. |
What to do next
-
If an active policy references your object, deploy configuration changes.