Software Secure Workload
Activity Configure

If There Are Too Many Policies for the Agent

If the complete set of applicable concrete policies cannot be pushed to a particular agent, the latest version of the policies is not pushed.

Background: There is a limit to the number of policies supported on each agent. Limits also apply to policies enforced using cloud connectors. You may find the information in Configuration Limits in Secure Workload helpful.

Before you begin

Use this procedure to resolve this problem if Verify That Enforced Policies Are Being Pushed to Agents indicates that the agent cannot accommodate the full set of enforced policies.

Procedure

1

Navigate to the primary workspace for an affected scope.

2

Modify the policies in the primary workspace:

Try to reduce the number of policies and reduce any long lists of IP addresses in consumer or provider.

For example, consolidate existing policies, and/or base policies on subnets rather than on huge lists of IP addresses.

For policies enforced using a cloud connector, you may also be able to increase any limits that are imposed by the platform. See the documentation for your cloud platform.

3

After you have made changes, enforce the latest version of the workspace and check again for skipped policies.

4

Repeat this procedure for any other scopes experiencing this issue.