Software Secure Workload
Activity Configure

View Enforced Policies for a Specific Workload (Concrete Policies)

Use this procedure to view all enforced policies for a specific workload (that is, the concrete policies for that workload). This view is useful because all policies in a workspace may not apply to every workload in the workspace, and because policies in multiple workspaces may apply to a particular workload (for example, inherited policies in parent or ancestor scopes).

Concrete policies are listed in priority order. For more information about the effects of priority, see the Policy Priorities section.

Before you begin


 

Concrete policies include only policies in enforced workspaces. If a workspace is not enforced, any policies that would apply to the workload if the workspace were enforced do not appear in the list.

Procedure

1

You can navigate to the Concrete Policies page for a workload from the Inventory page or from the workspace:

To navigate from the Scopes and Inventory page:

  1. Choose Organize > Scopes and Inventory.

  2. Search for the IP address of the workload of interest and click it.

    The Workload Profile opens in a separate tab.

    In general, except for cloud-based workloads that are managed without agents, Kubernetes, and OpenShift workloads, if the IP address appears in the IP Addresses tab and not in the Workloads tab, this means that an agent is not installed on the workload, so policies cannot be enforced, and there is no concrete policies list.

To navigate from the Segmentation page:

  1. Choose Defend > Segmentation.

  2. Click the scope.

  3. Click the Primary workspace.

  4. Click Manage Policies.

  5. Click the Matching Inventories tab.

  6. Search for the IP address of the workload of interest and click it.

  7. In the panel that opens on the right, click View Workload Profile.

    The Workload Profile opens in a separate tab.

2

From the menu on the left side of the Workload Profile page, click CONCRETE POLICIES.

3

Click a row to view details.

For more information, see the Concrete Policies tab.
4

To see the amount of traffic that has hit each policy:

  1. Click Fetch All Stats.

  2. Click each policy of interest.

5

To view information about Kubernetes or OpenShift workloads, click CONTAINER POLICIES.

What to do next

Choose Monitor > Enforcement Status for status of concrete policies, for example to see if any policies have been skipped. For details, see the Enforcement Status section.