Create a Policy to Quarantine Vulnerable Workloads
You can:
-
Create policies in advance, to automatically quarantine workloads with specific known vulnerabilities or a vulnerability severity threshold you specify.
-
Create policies, to immediately quarantine workloads with detected known vulnerabilities that you deem sufficiently problematic.
This topic outlines the process for doing either.
Before you begin
Look at the View Vulnerability Dashboard to see what policies are required.
Procedure
1 |
Create an inventory filter that defines the vulnerabilities or the vulnerability severity threshold that you want to quarantine: |
2 |
Create a policy to quarantine affected workloads: For general instructions, see Manually Create Policies. Recommendations:
|
3 |
Review, analyze, and enforce the policy or policies. |
What to do next
Create an alert so you are notified when traffic hits this policy so you can remediate the problem and restore traffic to the vulnerable workload. See Configure Alerts.