Reading up on SGT. From cisco live presentations and cisco feature navigator, it looks like only the 6500 and nexus 7k are able to act as SG enforcement nodes (support for SGACL). However, it looks like the 4500-x might also support SGACL.
The Cisco Catalyst 4500-X offers advanced security capabilities with Cisco TrustSec. Cisco TrustSec is an intelligent and scalable access control solution that mitigates security access risks across the entire network. As part of Cisco TrustSec, the Cisco Catalyst 4500-X provides advanced 802.1X features; Network Device Admission Control (NDAC) to authenticate the connecting switch; Security Group Tagging (SGT); policy enforcement using Security Group Access Control Lists (SGACLs); and MACsec, a data link layer encryption technology that makes sure of data integrity by encrypting the data traffic between switches
Can anyone confirm?