Before you automatically discover policies, verify that the workloads on which policy discovery will be based are in fact the set of workloads you expect. Discovered policies will be generated from flow data captured by agents on these workloads.
Procedure
1 |
From the navigation menu on the left, choose Defend > Segmentation.
|
2 |
Click the scope for which you want to discover policies.
|
3 |
Click the workspace in which you want to discover policies.
|
4 |
Click Manage Policies.
|
5 |
Click Matching Inventories.
|
6 |
If you discover policies for a single scope:
-
Click Uncategorized Inventory
This page shows workloads that are not also members of child scopes. (In standard automatic policy discovery, policies and clusters are generated in this scope only for workloads that are not also members of child scopes.)
-
Click IP addresses.
IP addresses on this page do not have Secure Workload agents installed.
Because they do not have agents that are installed, these IP addresses are not considered during automatic policy discovery for this scope UNLESS:
-
Policy is being managed via a cloud connector
-
The IP addresses are container-based inventory, in which case individual workloads appear on the Pods tab, or
-
The workloads happen to communicate with a workload in this scope that is considered during policy discovery.
Before discovering policies, consider installing agents on workloads that need them and allowing some time to pass for flow data to accumulate.
-
Click Workloads.
Policies and clusters are generated only for workloads on this page and for IP addresses on the IP addresses tab that meet the criteria specified above for consideration.
-
If you have Kubernetes or OpenShift inventory, you will see a Services tab and a Pods tab.
If you have installed agents on your Kubernetes/OpenShift workloads, check the inventory on those tabs as well.
-
If you have load-balancer inventory, that inventory appears on the Services tab.
|
7 |
If you discover policies for a branch of the tree:
-
Click All Inventory
This process generates policies (but not clusters) for all workloads in this scope, whether they are also members of child scopes.
-
Click IP addresses.
IP addresses on this page do not have Secure Workload agents installed.
Because they do not have agents installed, these IP addresses will not be considered during automatic policy discovery for this scope unless:
-
Policy is managed via a cloud connector
-
The IP addresses are container-based inventory, in which case individual workloads appear on the Pods tab, or
-
The workloads happen to communicate with a workload in this scope that is considered during policy discovery.
Before discovering policies, consider installing agents on these workloads and allowing some time to pass for flow data to accumulate.
-
Click Workloads.
Policies are generated only for workloads on this page and for IP addresses on the IP addresses tab that meet the criteria specified above for consideration.
-
If you have Kubernetes or OpenShift inventory, you will see a Services tab and a Pods tab.
If you have installed agents on your Kubernetes/OpenShift workloads, check the inventory on those tabs as well.
-
If you have load-balancer inventory, that inventory appears on the Services tab.
|
8 |
Verify that the workloads are the set you expect.
|