Software Secure Access
Activity Manage

Combining Multiple Destinations in a Rule (Boolean Logic)

If an internet access rule includes multiple destinations, the following boolean logic applies:

  • All types of destinations, and all destinations within a type, are treated as using the boolean OR operator. Traffic to each destination that you specify in a rule matches the rule.
    • For example, if you specify a content category and an application list as destinations in a single rule, traffic to any destination that is a member of either group will match the rule.
  • If you specify ANY for the protocol, then all traffic on the protocols (TCP, UDP, ICMP) supported by internet rules matches the rule, regardless of any other destinations that you specify.
  • If you enter in values of different types (IP address, port, protocol), traffic matches if any of the specified values match the rule.
    • For example, if you specify an IP address and a port, traffic to any IP address on the specified port matches the rule, as does traffic to the specified address on any port.