Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Attention: The Community will be in read-only mode on 12/14/2017 from 12:00 am pacific to 11:30 am.

During this time you will only be able to see content. Other interactions such as posting, replying to questions, or marking content as helpful will be disabled for few hours.

We apologize for the inconvenience while we perform important updates to the Community.

New Member

ISE Inline Posture and SGT

ISE Experts,

I'm doing research preparing for an SGT deployment.

We have Cisco ASA for VPN and iPEP for Posture enforecement.

The questions are:

1) Does iPEP support SGT?

2) Can I utilize SGT for VPN users?



Everyone's tags (7)

ISE Inline Posture and SGT

The Cisco  TrustSec (CTS) architecture secures networks by establishing domains of  trusted network devices. Once a network device authenticates with the  network, the communication on the links between devices in the cloud is  secured with a combination of encryption, message integrity checks, and  replay protection mechanisms.

CTS  use the user and device identification information acquired during the  authentication phase to classify packets as they enter the network. CTS  maintains classification of each packet or frame by tagging it with a  security group tag (SGT) on ingress to the network so that it can be  identified for applying security and other policy criteria along the  data path. The tags allow network intermediaries such as switches and  firewalls to enforce access control policy based on the classification.

Please  check the below links which may be helpful for you in configurations:


Cisco Employee

Using Ipep for SGT probably

Using Ipep for SGT probably is not a use case that we've seen so far and i cant be sure if it was tested.

However with ASA 9.2 you can enforce SGT based policies on the VPN users without needing an Ipep.



ISE Escalation engineer | CCIE#28227

Cisco systems.

Here , in this scenario , I

Here , in this scenario , I think the PSN would support SGT over ASA, not ipep

Cisco Employee

Ipep would not be needed if

Ipep would not be needed if you use the tech note i pointed too. More over ,Ipep was a solution that was needed for VPN scenarios when ASA was not capable of supporting COA. Now with 9.2 since we do and this architecture is a more elegant solution than adding another hop (provided you're in Routed mode).


Hi,As we know that SGT is


As we know that SGT is Cisco-proprietary tagging system.
we just need to confirm before deployment, does NAD devices support SGT ?
so with ASA 9.2 you can use SGT for VPN users.

As per my understanding iPEP is another part it would not have any issue 
with SGT enforcement policies.

CreatePlease to create content