The following restrictions are applicable when running Cisco TrustSec in enforcement mode or inline tagging mode. These restrictions do not apply when these switches are used as an SXP speaker: - An IP subnet address cannot be statically mapped to a Security Group Tag (SGT). - If a port is configured in multi-authentication mode, all hosts connecting to that port must be assigned the same SGT. - Cisco TrustSec enforcement mode on a VLAN trunk line supports only up to eight VLANs. If more than eight VLANs are configured on a VLAN trunk link and Cisco TrustSec is enabled on those VLANs. https://www.cisco.com/c/en/us/td/docs/switches/lan/trustsec/configuration/guide/trustsec/sxp_conf ig.html#Restriction%20for%20SGT%20Exchange%20Protocol