Shared Security Policy Rules

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Shared Security Policy Rules

L4 Transporter

When you have multiple device groups, are you able to create shared security policies?  When I try to select shared and create a security policy rule, the zones are blank.

 

Only workaround I can seem to find is create a security policy in one device group and clone it to the others

1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

Hi @ce1028 ,

 

Great question!  I didn't realize zones were a limitation of the Shared device group.  The zones are populated by the devices or reference templates in the device group.  Since Shared is read only, it appears that you cannot save those fields.

 

What you can do is create a new device group, e.g. "Shared Rules", under Shared and make it the parent of the other device groups.  (You can have 4 device groups in a hierarchy).  You can add a reference template with zones to Shared Rules.  Then you can create share security policies for all of your firewalls in this one device group.

 

Thanks,

 

Tom

 

Hi @ce1028 ,

 

I have an update!  You can use Shared for common policy rules!  You can move a rule from another device group and the zones work fine.  Also, once you have imported the zones in a rule, they show up in the drop down for new rules.  You could also type the zone in manually without the dropdown.

 

Hope this helps,

 

Tom

Help the community: Like helpful comments and mark solutions.

View solution in original post

2 REPLIES 2

Cyber Elite
Cyber Elite

Hi @ce1028 ,

 

Great question!  I didn't realize zones were a limitation of the Shared device group.  The zones are populated by the devices or reference templates in the device group.  Since Shared is read only, it appears that you cannot save those fields.

 

What you can do is create a new device group, e.g. "Shared Rules", under Shared and make it the parent of the other device groups.  (You can have 4 device groups in a hierarchy).  You can add a reference template with zones to Shared Rules.  Then you can create share security policies for all of your firewalls in this one device group.

 

Thanks,

 

Tom

 

Hi @ce1028 ,

 

I have an update!  You can use Shared for common policy rules!  You can move a rule from another device group and the zones work fine.  Also, once you have imported the zones in a rule, they show up in the drop down for new rules.  You could also type the zone in manually without the dropdown.

 

Hope this helps,

 

Tom

Help the community: Like helpful comments and mark solutions.

Thanks @TomYoung .  I did not realize it either until now.!

  • 1 accepted solution
  • 3086 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!