- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
10-10-2018 06:48 AM
Greetings
I am trying to find a Best Practice for blocking applications at certain times for a certain group of users.
As i see it
I create a policy for these users allowing them access to a few applications. now if i wanted to allow them acces to Instagram or Netlix as an example.
I could
1) add Netflix in tho the allowed group, then
A) Create a block Policy on a schedual AFTER the allow Policy.
B) Create a block Policy on a schedual BEFORE the allow Policy.
2) Create a an ALLOW Policy for Netflix on a schedual.
But i dont really know which option works Best.
Can someone provide some insight or point me to a Knowledge base that might explain the best way to do this?
Thank you
10-10-2018 08:07 AM
Hello,
While I have not seen an article on this yet. I am in favor of the whitelist approach method. In your example it would be option 2. This way its still DENY ALL and allow by exception.
Hope that helps!
10-10-2018 12:08 PM
This is one of those 'depends on environment/people' type of things. I would personally go with option 2, knowing that if it didn't match the allow policy it would hit the interzone-default policy. However, I'm also envolved in enviroments where the other administrators can't seem to visulize how the traffic is supposed to process unless I did something like option 1. Either one obviously works perfectly fine.
10-10-2018 08:07 AM
Hello,
While I have not seen an article on this yet. I am in favor of the whitelist approach method. In your example it would be option 2. This way its still DENY ALL and allow by exception.
Hope that helps!
10-10-2018 12:08 PM
This is one of those 'depends on environment/people' type of things. I would personally go with option 2, knowing that if it didn't match the allow policy it would hit the interzone-default policy. However, I'm also envolved in enviroments where the other administrators can't seem to visulize how the traffic is supposed to process unless I did something like option 1. Either one obviously works perfectly fine.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!