- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
04-07-2022 02:28 PM
Hi Guys,
I tried to find out what is the difference between "Add to This Rule" versus "Add to Exiting rule" in a security policy.
Thanks
04-07-2022 04:23 PM
Assuming that you're talking about policy optimization on the "Apps Seen" tab, it means what you would expect. The Add to This Rule option will add the app specified to the rule that captured the traffic initially, while the Add to Existing Rule will add the application into a different entry that already exists in your rulebase.
As an example, if you have any sort of "catch-all" rule present to identify traffic, you'd likely never want to "Add to This Rule" since it would completely break the purpose of the rule; instead you would either "Add to Existing Rule" (say if you want to add it to some sort of "allowed applications" rule or something like that), or you would "Create Cloned Rule" to create a new entry and not break the "catch-all" entry.
04-07-2022 04:23 PM
Assuming that you're talking about policy optimization on the "Apps Seen" tab, it means what you would expect. The Add to This Rule option will add the app specified to the rule that captured the traffic initially, while the Add to Existing Rule will add the application into a different entry that already exists in your rulebase.
As an example, if you have any sort of "catch-all" rule present to identify traffic, you'd likely never want to "Add to This Rule" since it would completely break the purpose of the rule; instead you would either "Add to Existing Rule" (say if you want to add it to some sort of "allowed applications" rule or something like that), or you would "Create Cloned Rule" to create a new entry and not break the "catch-all" entry.
04-22-2023 12:17 AM
I find it confusing, wouldn't it be easier to say: 'add to this rule' and "add to other rule" instead?
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!