Create a shared ruleset
You can use the API to create shared allow or block rules and apply the ruleset to
other computers. This can be useful if you have many identical computers (such as
a load balanced web server farm). Shared rulesets should be applied only to computers
with the exact same inventory.
Procedure
- Use the API to build a computer's shared allow and block rules. For more
information, Create a Shared Ruleset. If you want to examine the shared
ruleset before you deploy it, see View and change Application Control rulesets.
- Go to Computer or Policy editor Application Control.
- In the ruleset section, make sure Inherit settings is not selected, and then select Use a shared ruleset. Indicate which shared rules to use.These settings are hidden until you use the API to create at least one shared ruleset. If you have not created any shared rulesets, or if you have chosen to retain the default settings, each computer keeps its own allow and block rules locally. Changes to local rules do not affect other computers.
- Click Save.The next time that the agent on the computer connects with Workload Security, the agent applies those rules.If you see an error saying that the ruleset upload was not successful, verify that network devices between the agent and Workload Security allow communications on the heartbeat port (see port numbers).
What to do next
Change from shared to computer-specific allow and block rules
If the computer is currently using shared allow or block rules created via the API,
you can <madcap:annotation madcap:createdate="2016-10-13T12:59:32.7307911-04:00" madcap:creator="courtneys"
madcap:initials="CS" madcap:comment="Does this overwrite block rules, too? Is there
a way to reset them?" madcap:editor="courtneys" madcap:editdate="2016-10-13T12:59:33.3398286-04:00">change
it to use local rules</madcap:annotation>. Application Control scans the file system
for all currently-installed software and creates an initial ruleset for it, similar
to when you first enabled Application Control.
![]() |
WARNINGBefore you start, verify that only good software is currently installed. Rebuilding
the ruleset allows all currently installed software, even if it is insecure or malware.
If you are not sure what is installed, the safest approach is to make a clean install,
and then enable Application Control.
|
The following steps configure a computer's agent to use a local ruleset. If you want
all computers to use local rules, edit the setting in the Policies tab instead.
Procedure
- Go to .
- In the ruleset section, deselect Inherit settings (if necessary), and then select Use local ruleset initially based on installed software.
- Click Save.
What to do next
To verify the change, the next time the agent and Workload Security connect, look
for event log messages about building the Application Control
ruleset.