Verify Enforcement Works as Expected
Check Agents
Check for Escaped and Rejected Flows
In the menu on the left side of the screen, click Overview.
On the Security Dashboard page, look at the Segmentation Compliance Score.
If this is less than 100, you may have escaped or rejected flows, either of which indicates a policy configuration issue.
For details, see Segmentation Compliance Score.
For more information about investigating these situations, see Policy Analysis Results: Understand the Basics and subtopics. (The information in these topics applies to enforced policies shown on the Enforcement tab and to analyzed policies shown on the Policy Analysis tab.)
Add any missing policies, or modify existing policies, for example, by adding additional protocols/ports, to allow required legitimate traffic.
Then reanalyze before reenforcing.