Agent Enforcement on Solaris 11.4 Platform
On the Solaris 11.4 platform, the Secure Workload agent uses PF(Packet Filter) utilities to enforce network policies. Solaris 11.4 supports IPv6 enforcement.
Caveats
Policy enforcement for the Shared-IP Solaris Zones is carried out by the agent installed in the Global Zone.
Host Firewall Backup
When enforcement is enabled for the first time in an Agent Config Profile, the agents running on Solaris 11.4 hosts, before taking control of the host firewall, store the current content of ippool and pffilter into /opt/cisco/tetration/backup. Successive disable or enable transitions of enforcement configuration do not generate backups. The directory is not removed upon agent uninstallation.