Create InfoSec Policies to Block Traffic from Outside Your Network
Use this procedure to quickly create a complete set of policies to control traffic entering your network from outside the network. The default set of policies allows only traffic using common ports and protocols and denies all other traffic. You can modify the default policy set to meet your needs.
Before you begin
Use this procedure if the following criteria are met:
-
Your scope tree has a scope that is named Internal immediately below the root scope.
This scope's members include, or will include, subnets encompassing all workloads on your internal network.
-
The Internal scope does not yet have any policies defined in it.
|
Alternatively, you can use the InfoSec template available from Defend > Policy Templates to accomplish this with a few additional steps. |
Procedure
1 |
Choose Defend > Segmentation, |
2 |
Click the Internal scope and click the primary workspace. If the Primary workspace does not yet exist, click the + button to create it. |
3 |
Click Manage Policies. |
4 |
Click Add InfoSec Policies. |
5 |
Verify that all the policies in the list, including protocols and ports, are policies you want and delete and modify policies as desired. |
6 |
Click Create. |
What to do next
(Optional) Add any additional policies to your Internal scope, such as policies that allow certain external traffic to specific workloads.
Place any specific policies below the more general policies in the list.