: Add a Path Policy Rule
Focus
Focus

Add a Path Policy Rule

Table of Contents

Add a Path Policy Rule

Learn how to add a path policy rule in
Prisma SD-WAN
.
Path policy rules define network paths for application sessions to leverage. Path Policy Rules use network contexts, applications, destination zones, prefixes, ports, and protocols. Layer 3 paths can be private or internet paths, VPN, or standard VPNs. You can directly add policy rules to a simple path stack by clicking a simple path stack and then clicking
Add Rule
. For advanced stacks, select a stack, then a policy set within the stack, and then add policy rules to the policy set.
  • Add a path policy rule to a simple path stack.
    1. Select
      Manage
      Policies
      Path
      Path Stacks
      Simple
      Select a Stack
      Add Rule
      .
    2. Select an order for the rule.
      Policy rules follow explicit ordering and implicit ordering. In explicit ordering, each rule within a policy set has an order number that is used to explicitly order rules overriding an implicit order, a set of match criteria, and a set of actions. If two rules have the same order, then the rules follow implicit ordering wherein policy rules with more specific attributes get precedence over rules with less specific attributes.
      • Enter a
        Name
        for the policy rule, and optionally enter description and tags.
      • Enter an
        order
        between 1-65535 for the policy rule.
        An order of 1 indicates the highest priority for the policy rule. The default is 1024.
      • (Optional)
        Select
        Disable Rule
        if you do not want the ION device to consider this rule.
    3. (Optional)
      Configure network contexts.
      • On the
        Network Contexts
        screen, select a previously configured
        Network Context
        or click the
        +
        icon to create a network context.
    4. (Optional)
      Configure Prefixes.
      On the
      Prefixes
      tab, select a
      Source Prefix
      and a
      Destination Prefix
      .
    5. (Optional)
      Add users or user groups.
      On the
      Users
      tab, select a
      User
      and/or a
      Group
      from the
      User/Group
      drop-down.
    6. (Optional)
      Select applications.
      On the
      Apps
      tab, select the applications to apply the policy rule. You can select 256 applications for one policy rule.
      You can filter applications based on:
      • For sites 6.0.1 or above—Select this option to view system applications from PANW, applications common to PANW and
        Prisma SD-WAN
        , and custom applications defined in
        Prisma SD-WAN
        .
      • For sites below 6.0.1—Select this option to view legacy system applications in
        Prisma SD-WAN
        , applications common to PANW and Prisma SD-WAN, and custom applications defined in
        Prisma SD-WAN
        .
      • For any site—Use this option to view applications common to PANW and
        Prisma SD-WAN
        along with custom applications defined in
        Prisma SD-WAN
        .
      (Optional)
      You can check the type of application -
      System (PANW, CGX)
      ,
      System (CGX)
      , or
      Custom
      by selecting the application first and then using the filters to view the type of application.
    7. Configure paths.
      On the
      Paths
      tab, choose
      Active/Backup/L3 Failure Paths
      for the application from the drop-down list.
      Select an
      Overlay
      and a
      Circuit Category
      for a path. You cannot repeat a combination of an overlay and a circuit category for a policy rule.
      You must configure an active path. You can optionally configure backup paths and L3 failure paths. You can configure an L3 failure path without configuring a backup path.
      In ION devices running 5.2.1 and higher versions, the default setting moves flows back to the active path in the policy as soon as the active path becomes available.
    8. Select Service and DC Groups.
      Select Service & DC Groups, and then select Active/Backup Service & DC Groups from the drop-down.
      If the
      Required
      check box is selected, traffic will always transit through the Service and DC Groups. If not selected, traffic may or may not transit through the Service and DC Groups per policy. You cannot select
      Required
      , if you have selected at least one direct path in the
      Paths
      tab.
    9. Confirm the information displayed in the
      Summary
      tab and then click
      Save & Exit
      .
  • Add a path policy rule to an advanced path policy set.
    1. Select
      Manage
      Policies
      Path
      Path Stacks
      Advanced
      Select a Stack
      Add Rule
      .
    2. Follow the steps above for adding a path policy rule to a simple policy stack.

Recommended For You