Actions you can perform on Apps Seen: Create Cloned Rule—Clones the current
rule. When migrating from port-based rules to application-based
rules, clone the port-based rule first and then edit the clone to
create the application-based rule that allows the traffic. The cloned rule
is inserted above the port-based rule in the policy list. Use this
migration method to ensure that you don’t inadvertently deny traffic
that you want to allow—if the cloned rule doesn’t allow all the
applications you need, the port-based rule that follows allows them.
Monitor the port-based rule and adjust the (cloned) application-based
rule as needed. When you’re sure the application-based rule allows
the traffic you want and only unwanted traffic filters through to the
port-based rule, you can safely remove the port-based rule. Cloning
offers similar advantages for applications seen in the New
App Viewer and enables you to move newly identified
cloud applications as well as content-provided applications into
Security policy rules that enable you to control the application
and access. You can select adding applications to a cloned
rule individually, in an Application Group, or in an Application Filter. Add to This Rule (Not available for
New App Viewer)—Adds applications from Apps Seen to the rule. Adding
applications to the rule transforms a rule configured to match Any application
(a port-based rule) to an application-based rule that allows the
applications you specify (the new application-based rule replaces the
port-based rule). The rule denies any applications that you don’t
add just as with any other application-based rule. Be sure to identify
all applications you want to allow and add them to the rule so you
don’t accidentally deny an application. Add to Existing Rule—Adds applications
from Apps Seen to an existing application-based (App-ID) rule. For
example, this enables you to clone an App-ID-based rule from a port-based
rule and then add more applications seen on port-based rules to
that App-ID rule later. For applications seen in the New
App Viewer, you can organize newly identified cloud-based and content-based applications
into sensible Security policy rules as new apps are discovered. You
can select adding applications to an existing rule individually,
in an Application Group, or in an Application Filter. Match Usage (Not available for New
App Viewer)—Moves all Apps Seen into the rule (they are listed under
Apps on Rule after you Match Usage). If you
are certain that the rule should allow all listed applications, Match
Usage is very convenient. However, you must be certain
that all listed applications are applications you want to allow
on your network. If many applications have been seen on the rule
(for example, on a rule that allows web-browsing), it’s better to
clone the rule and transition to an application-based rule. Match
Usage works well for simple rules with well-known applications.
For example, if a port-based rule for port 22 has only seen SSH
traffic (and that’s all it should see), it’s safe to Match Usage.
The Clone, Add to
Rule, and Add Apps to Existing Rule dialogs
help to ensure that applications don’t break and enable you to future-proof
the rule by including relevant individual applications that are
related to the applications you’re cloning or adding to a rule. |