If you're using Security Group Tags (SGTs)
in a Cisco TrustSec network, inline firewalls in Layer 2 or Virtual
Wire mode can now inspect and enforce the tagged traffic. Layer 3
firewalls in a Cisco TrustSec network can also inspect and enforce
SGT traffic when deployed between two SGT exchange protocol (SXP)
peers. Processing of SGT traffic works
by default and without any configuration changes. Because the firewall
does not use SGTs as match criteria for security policy enforcement,
you should continue to define SGT-based policy in the same way you
do today. |