Create a security group tag object

This task allows you to add a security group tag object to enforce network access policies based on SGT.

You can create security group tag objects only in the global domain. A Control license is required for Classic devices. Any Smart License provides coverage for Smart Licensed devices.

Before you begin

  • Disable ISE or ISE-PIC connections because custom SGT objects cannot be created if either is used as an identity source.

    Click Integrations > Identity > Identity Sources, click None, then click Save.

  • See Best practices for ISE/ISE-PIC integration for guidelines for using the identity source.

Follow these steps to create a security group tag object:

Procedure


Step 1

Click Objects.

Step 2

Click External Attributes > Security Group Tag.

Step 3

Click Add Security Group Tag.

Step 4

Enter a Name.

Step 5

Optionally, enter a Description.

Step 6

In the Tag field, enter a single SGT.

Step 7

Click Save.


What to do next

  • If an active policy references your object, deploy configuration changes.