Software Secure Workload
Activity Configure

Include Data From Load Balancers and Routers When Discovering Policies

You can upload data from load balancers and routers to inform automatic policy discovery.

To access the following options, click Advanced Configurations in the automatic policy discovery settings and look at the "Side Informaton" or "sideinfo" section.

Option

Description

SLB Config

(Upload load balancer configurations)

To download data from your load balancer in the correct format, see Retrieving LoadBalancer Configurations.

Supported formats for uploading loadbalancer configs:

  • F5 BIG-IP

  • Citrix Netscaler

  • HAProxy

  • Others:

    Use the Normalized JSON schema.

    You must convert any unsupported load balancer config into this schema.

    This simple schema includes basic information on Virtual IPs (VIPs) and backend IPs.

    To download a sample JSON file, click the info button beside SLB Config.

Upload Route Labels

You can upload a list of provisioned subnets/routes from the routers to help partition hosts based on pre-provisioned set of subnets. The clustering results generated by automatic policy discovery never span the subnet boundaries as defined by the uploaded data. You can modify the results after automatic policy discovery is complete.

To download a sample JSON file, click the info button beside Route Labels.


 

Clusters do not span partition boundaries, meaning a cluster computed by automatic policy discovery does not contain target workloads from two different partitions. Partitions are computed from the uploaded load balancer or router data. However, you can freely move workloads from one cluster to another, for example by changing cluster query definitions (manual cluster editing), or disable the upload of any side info.

To view or delete a previously uploaded Load Balancer (SLB Config) or Route Labels file:

  1. Click into the respective box labeled Select a source for this side information.

    A list of uploaded files will appear.

  2. Click the download or trash icon beside the file to view or delete.

    Uploaded Side Information
    Figure 1: Uploaded Side Information