Software Secure Workload
Activity Configure

Configure Policies for Windows Attributes

For more granularity when enforcing a policy on Windows-based workloads, you can filter network traffic by:

  • Application Name

  • Service Name

  • User Names with or without User Groups

This option is supported in both WAF and WFP modes. Windows OS-based filters are categorized as consumer filters and provider filters in the generated network policy. The Consumer filters filter the network traffic that is initiated on the consumer workload and Provider filters filter the network traffic that is destined for the provider workload.

Before you begin

This procedure assumes you are modifying an existing policy. If you have not yet created the policy to which you want to add a Windows OS-based filter, create that policy first.


 

See Caveats and Known limitations for policies involving Windows attributes.

Procedure

1

In the navigation pane, click Defend > Segmentation.

2

Click the scope that contains the policy for which you want to configure Windows OS-based filters.

3

Click the workspace in which you want to edit the policy.

4

Click Manage Policies.

5

Choose the policy to edit.


 

Consumer and Provider must include only Windows workloads.

6

In the table row for the policy to edit, click the existing value in the Protocols and Ports column.

7

In the pane on the right, click the existing value under Protocols and Ports.

In the example, click TCP : 22 (SSH) .

8

Click Show advanced options.

9

Configure consumer filters based on Application name, Service name, or User name.

  • The application name must be a full pathname.

  • Service name must be a short service name.

  • User name can be a local user name (For example, tetter) or domain user name (For example, sensor-dev@sensor-dev.com or sensor-dev\sensor-dev)

  • User group can be local user group (For example, Administrators) or domain user group (For example, domain users\\sensor-dev)

  • Multiple user names and/ or user group names can be specified, separated by ",".(For example, sensor-dev\@sensor-dev.com,domain users\\sensor-dev)

  • Service name and User name cannot be configured together.

10

Configure provider filters based on Application name, Service name, or User name.

Follow the same guidelines as given for consumer filters in the previous step.

11

Enter the paths to the binary, as applicable.

For example, enter c:\test\putty.exe

12

Click Update.