You can switch between rulesets, but it is important to save changes on the
Policies tab for a specific ruleset before switching to another. A rule can be
used in more than one ruleset, providing further flexibility in managing network
security.
DCF rulesets are supported in Controller 8.0 or later. If you started using DCF
rulesets in Controller 8.0, two predefined rulesets were created: V1 Policy List
(editable) and Post Rules Policy List (non-editable). The former contained all
existing legacy rules (created prior to Controller 8.0) and the Greenfield Rule.
The latter contained the DefaultDenyAll rule. In Controller 8.0, two predefined
rulesets will be available: V1 Policy List (editable) and Post Rules Policy List
(non-editable). The former will contain all existing legacy rules (created prior
to Controller 8.0) and the Greenfield Rule. The latter will contain the
DefaultDenyAll rule. After monitoring or protecting VPC/VNets, rules are added
to the Egress Protection Policy List ruleset. This ruleset is created
automatically when you monitor or protect VPC/VNets, and it contains the rules
that are created as part of the monitoring or protection workflows. The legacy
DefaultDenyAll rule is moved from the Post Rules Policy List (8.0) to the Legacy
Default Deny Ruleset, which can be deleted. The Greenfield Rule will no longer
be created by default and is being replaced by the zero trust Default Action
Rule.
Security Control Templates
Aviatrix provides Security Control templates built from Aviatrix-provided threat intelligence feeds. Use a template to add threat-detection rules to your environment without writing custom rules. To explore available templates, go to Dashboard > Security Control, then click Explore Recommended Security Control. Current templates include Common Threats. Click Add on a template to apply it. Each Security Control you add starts in the Monitored state, which logs matching traffic without blocking it. Review the matched traffic on the Dashboard, and when you are ready to block that traffic, switch the control to Protect. You can switch a control back to Monitored at any time.The Dashboard’s traffic details depend on Log Enrichment, which is in
Preview and turned off by default. Turn on Log Enrichment on **Security
Distributed Cloud Firewall > Settings** to see enriched traffic detail for a Security Control’s matched traffic.