Software Secure Workload
Activity Configure

Agent Enforcement on Solaris 11.4 Platform

On the Solaris 11.4 platform, the Secure Workload agent uses PF(Packet Filter) utilities to enforce network policies. Solaris 11.4 supports IPv6 enforcement.

Caveats

Policy enforcement for the Shared-IP Solaris Zones is carried out by the agent installed in the Global Zone.

Host Firewall Backup

When enforcement is enabled for the first time in an Agent Config Profile, the agents running on Solaris 11.4 hosts, before taking control of the host firewall, store the current content of ippool and pffilter into /opt/cisco/tetration/backup. Successive disable or enable transitions of enforcement configuration do not generate backups. The directory is not removed upon agent uninstallation.