Creating a Basic Access Control Policy
When you create a new access control policy, it contains default actions and settings. After creating the policy, you are immediately placed in an edit session so that you can adjust the policy to suit your requirements.
Procedure
1 |
Choose . |
||
2 |
Click New Policy New Policy. |
||
3 |
Enter a unique Name and, optionally, a Description. |
||
4 |
Optionally, choose a base policy. If an access control policy is enforced on your domain, this step is not optional. You must choose the enforced policy or one of its descendants as the base policy. If you select a base policy, the base policy defines the default action and you cannot select a new one in this dialog box. Logging for connections handled by the default action depends on the base policy. |
||
5 |
When you do not select a base policy, specify the initial Default Action:
When you select a default action, logging of connections handled by the default action is initially disabled. You can enable it later when you edit the policy.
|
||
6 |
Optionally, choose the devices to assign to the policy. To narrow the devices that appear, enter a search string. The list includes both devices and device templates. If you want to deploy this policy immediately, you must perform this step. |
||
7 |
Click Save. The new policy opens for edit. You can add rules to it and make other changes as needed. See Editing an Access Control Policy . |