Procedure
- Go to .
- Click Add.
- Specify a policy name between 1 and 64 characters.
- Optionally, specify a description between 1 and 128 characters.
- Enable or disable the policy.
- Configure Traffic source by selecting one of the
following:
-
AnyThe policy applies to all networks, Active Directory users/groups, and guest users.
-
Selected users and groupsThe policy applies only to specific Active Directory users or groups.Under the All users and groups section, search for and add the users/groups to include as a traffic source. You can choose users and groups only if Active Directory Services is configured and only from domains that are included in the Active Directory Services configuration.
Note
Deep Discovery Web Inspector uses CommonName (CN) to perform user/group searches when selecting users/groups as a traffic source. -
Selected network objectsThe policy applies only to specific network objects.Select and then move one or more objects from the available network objects list to the selected network objects list. You can create a new network object to include in the policy by clicking Add New Network Object.
-
Guest usersThe policy applies only to users that authenticate on the network using a designated guest account.
Note
You can configure exceptions if you chose Selected users and groups or Selected network objects as the traffic source. -
- Configure Domain objects by selecting one of the
following:
-
AnyThe policy applies to all domain objects.
-
Selected domain objectsThe policy applies only to specific domain objects.Move one or more objects from the available domain objects box to the selected domain objects box. You can create a new domain object to include in the policy by clicking on Add New Domain Object.
-
- Configure File types by selecting one of the
following:
-
AnyThe policy applies to all defined file types.
-
Selected file typesThe policy applies to only specific file types.Move one or more file types from the available file types box to the selected file types box. The available file types are predefined and cannot be configured.
-
- Select the Action.
-
AllowIf the traffic matches the policy, allow the traffic while bypassing scanning.
-
BlockIf the traffic matches the policy, block the traffic.
-
ScanIf the traffic matches the policy, scan the traffic and perform the appropriate action configured for each risk level.
-
- If you configured Scan as the
action, perform the following:
- Configure which action to take (Block or Monitor) for each risk level if this policy is matched.
- Enable or disable Patient-Zero.
- Click Save.
What to do next
Move the policy to the desired location within the policy list.