Software Secure Workload
Activity Configure

Configure, Edit, or Delete Inclusion Flow Filters

Use this procedure to create a list of inclusion filters for a single workspace, or a list of default inclusion filters that are available for all workspaces.

Procedure

1

Do one of the following:

To

Do This

Configure inclusion filters for a specific workspace

From the navigation pane, choose Defend > Segmentation, choose the workspace and click Manage Policies.

  • Click on the workspace for which you need to create the inclusion filter, expand the More dropdown below the AI Policy Discovery button. From the dropdown, choose PolicyDiscovery Flow Filters.

  • From the PolicyDiscovery Flow Filters page, click Create Flow Filter.

  • To create an inclusion filter, click the Inclusion tab and enter the details in the Create Flow Filter window.

Configure default inclusion filters that are available in any workspace

  • From the navigation pane, choose Defend > Segmentation,

  • Click the caret to expand the Tools menu and choose AI Policy Policy Discovery Configuration.

  • Scroll to the bottom of the page.

  • Click Default Flow Inclusion Filters.

2

Specify the parameters for the flows to include from consideration during policy discovery:

You do not need to enter values for all the fields. Any empty field is treated as a wildcard for matching flows.

Any conversation that matches all the fields of any inclusion filter is ignored for the purposes of policy creation and clustering.

Option

Description

Consumer

Matches conversations where the consumer address is a member of the selected scope, inventory filter, or (for workspace-specific exclusion filters only, cluster). You can specify any arbitrary address space by creating a new custom filter.

Provider

Matches conversations where the provider address is a member of the selected scope, inventory filter, or (for workspace-specific exclusion filters only, cluster). You can specify any arbitrary address space by creating a new custom filter.

Protocol

Matches conversations with specified protocol.

Port

Matches conversations with provider (server) port matching the specified port, or port range. Enter port ranges using a dash separator, for example, “100-200”

3

To edit or delete an inclusion filter, click either the Edit or the Delete button.

4

If you are configuring default inclusion filters:

When the configured filters are ready to use, return to the Default Policy Discovery Configuration page, and click Save to make the changes available to individual workspaces.

What to do next


 

Before discovering policies, ensure that:

  • inclusion filters are enabled by default in all workspaces.

  • Both types of inclusion filters are enabled in the Default Policy Discovery Configuration.

For more information, see Enable or Disable Inclusion Flow Filters.

Commit any scope changes, or the filters may not match (and therefore include) the expected flows. See Commit Changes.