Create Security Policy Rules
Table of Contents
Expand All
|
Collapse All
Prisma SD-WAN Docs
-
-
-
-
- AWS Transit Gateway
- Azure vWAN
- Azure vWAN with vION
- ChatBot for MS Teams
- ChatBot for Slack
- CloudBlades Integration with Prisma Access
- GCP NCC
- Service Now
- Zoom QSS
- Zscaler Internet Access
-
-
- ION 5.2
- ION 5.3
- ION 5.4
- ION 5.5
- ION 5.6
- ION 6.0
- ION 6.1
- ION 6.2
- ION 6.3
- ION 6.4
- New Features Guide
- On-Premises Controller
- Prisma Access CloudBlade Cloud Managed
- Prisma Access CloudBlade Panorama Managed
- Prisma SD-WAN CloudBlades
Create Security Policy Rules
Prisma SD-WAN allows you to create security policy rules
for zbfw.
Where Can I Use This? | What Do I Need? |
---|---|
|
|
Each security policy set is a collection of
security policy rules. The default security policy rules automatically assigned
to a security policy set cannot be changed, removed, or deleted.
You can create custom security policy rules to take precedence over
the default security policy rules.
You should configure general
permit any or deny any rules first, then add more specific access
and deny rules and have them listed in higher priority order so
that they evaluate before the broader rules.
- SelectManagePolicies Security(Original). Select a security policy set and then click Add Policy Rule.Type a rule name, (optional) description. Select the source zones and source filters to which this rule applies, and then click Next.Source zones specify where traffic originates. Source filters specify IP addresses that further refine the source zone traffic to which the rule applies.
- Select Any to apply this rule to all listed source zones and filters.De-select Any to select one or more specific source zones and source filters.Select the destination zones and destination filters to which this rule applies, then click Next.Destination zones specify the traffic destined. Destination filters specify IP addresses that further refine the destination zone traffic to which the rule applies. You can select more than one filter to apply to the traffic.
- Select Any to apply this rule to all listed destination zones and filters.De-select Any to select one or more specific destination zones and destination filters.Select Any to apply created rule to all listed applications or de-select Any to select one or more specific applications for this rule, then click Next.If you de-select Any, search for a specific application, filter using Categories, or sort by application name or modify the date.Select the action to take for traffic matching this rule, then click Next.Actions determine how the traffic from the specified source zone to the specified destination zone should respond.
- Select Deny denying traffic between the specified zones and filters.Select Reject to reject traffic between the specified zones and filters.Select Allow allowing traffic that matches the rule to be forwarded.Review the security rule summary and select Create & Exit to add the new security policy rule to its security policy set.