Cloud NGFW for Azure
Create a Rulestack on Cloud NGFW for Azure
Table of Contents
Expand All
|
Collapse All
Cloud NGFW for Azure Docs
Create a Rulestack on Cloud NGFW for Azure
Learn how to create a rulestack on Cloud NGFW for Azure.
Where Can I Use This? | What Do I Need? |
---|---|
|
|
Rulestacks defines access control (App-ID, URL Filtering) and threat prevention
behavior of Cloud NGFW resources. A Cloud NGFW resource uses your rulestack
definitions to protect the traffic by a two-step process. First, it enforces your
rules on the to allow or deny your traffic. Second, it performs content inspection
on the allowed traffic based on what you specify on the Security Profiles. A
rulestack includes a set of security rules, associated objects, and profiles similar
to device groups on Panorama.
Cloud NGFW for Azure supports a local rulestack. A Local rulestack consists of
local rules and manages the local rules. A local account administrator can associate
a local rulestack to an NGFW in their AWS account. To create and manage local
rulestacks, you must have the Local rulestack admin role.
In the Cloud NGFW, you can author local rulestacks if you are assigned the
LocalRuleStackAdmin role.
If you are
deploying the firewall for the first time and intend to use Strata Cloud Manager for policy
management, you must deploy a local rulestack first. Deploying a
local rulestack is free.
Complete the following procedure to create a local rulestack in Azure Portal.
- In the Azure Portal, use the search bar to locate the Local Rulestack .Click Create.Choose Subscription and Resource Group from their respective drop-downs in the Project details section of the Basics tab.Enter a descriptive Name for your rulestack.Enter the supported Region for your rulestack.Click the Tags tab.
- Enter the Name and Value.Click Review+create.Review the rulestack options you have selected and click Create.After successfully creating the local rulestack, register it in the Azure Portal by creating a customer support case. For more information, see Register for Support.