The config evaluation tool kind of tells me what I was already starting to think. That the data being passed back from the new controller isn't the same as what's being passed back from the old controller.
Here is where the NAC says I am failing the rule:
PASSED: The Device Type of: MAC Address: AC:37:43:4A:B2:79, IP Address: 10.147.16.52, Host Name: android-ef3622142e1ba508 passes the any criteria evaluation.
PASSED: The User: svanarts has LDAP attributes that match the ones defined in LDAP User Group: SJGH-LDAP-USERS.
FAILED: The Switch IP of: 10.140.20.14, Port: SJGH-ENTERPRISE, SSID: null, AP Name: null, AP MAC: null, AP Serial: null and AP Zone or Group: null and AP Location: null did not match this inclusive criteria.
Compare that with the old controller where I am passing the rule:
PASSED: The User: svanarts has LDAP attributes that match the ones defined in LDAP User Group: SJGH-LDAP-USERS.
PASSED: The Switch IP of 10.140.20.10, SSID: SJGH, AP Name: AP-272 MedStaff-Copy-Room-113, AP MAC: 20-B3-99-B6-7F-29, AP Serial: 13411855595D0000 and AP Zone or Group: null and AP Location: null did match this inclusive criteria.
PASSED: The Time of: Monday, October 31, 2016 8:55:47 AM PDT passes the any criteria evaluation.
PASSED: The Operating System Name of: passes the any criteria evaluation.
So on the new controller I am not seeing the SSID or AP Name being passed back from the controller to the NAC.