Manually Create Policies
Typically, you can manually create policies that apply broadly across your network.
For example, you can manually create policies to:
-
Allow access from all internal workloads to your NTP, DNS, Active Directory, or vulnerability scanning servers.
-
Deny access from all hosts outside your organization to hosts inside your network unless explicitly permitted.
-
Quarantine vulnerable workloads.
You can create absolute policies that cannot be overridden by more granularly applied policies, and default policies that can be overridden if a more specific policy exists.
You can create manual policies for scopes nearer the top of your tree.
Before you begin
-
(Optional) Consider using one of the templates available from Defend > Policy Templates.
-
(Optional) If you know you have a set of workloads that receive the same policies, use an inventory filter to group them so you can easily apply policies to the set. The inventory filter can apply to only one scope, or to workloads in any scope. See Create an Inventory Filter.
-
Make sure that the workloads in this scope are the workloads that you expect to be in this scope. See View Workloads in a Scope.
Procedure
1 |
Click Defend > Segmentation. |
2 |
In the list on the left, search for or navigate to the scope in which you want to create the policy. |
3 |
Click the scope and workspace in which you want to create the policy. If you haven't yet created the workspace for this scope, see Create a Workspace. |
4 |
Click Manage Policies. |
5 |
Click the Policies tab if it is not already selected. |
6 |
Click Add Policy. If you don't see an Add Policy button, see If the Add Policy Button Is Not Available. |
7 |
Enter information.
|
What to do next
Make sure the Catch-all action is appropriate for the workspace. See Policy Rank: Absolute, Default, and Catch-All.