Cloud NGFW policies don't support plain network tags at all.
Secure Tags are the only targeting mechanism — identity, not IP range.
Classic firewall rulesCloud NGFW policies
Attaches atPer network onlyGlobal, regional, or hierarchical
TargetingNetwork tags, service accountsSecure Tags only
Secure Tags are the same Resource Manager tags from Ch 1, applied to firewall targeting. A rule matching
env=production keeps working through a resize or migration — it matches identity, not an address.