Skip to main content
This section provides the purpose, elements, and actions performed on the Distributed Cloud Firewall pages.

Purpose

The Policies page creates and manages distributed firewall policies for securing traffic across the multi-cloud environments.

Elements

Distributed Cloud Firewall: Policies
  • + Rule button: Starts the workflow to create a new firewall rule.
  • Manage Rulesets: Opens the dialog to create, edit, or manage rulesets (groupings of rules). Create rulesets before adding rules to them (Controller 8.0 or later).
  • Actions button: Provides options to Reset Traffic Count, Turn On Enforcement, Turn Off Enforcement, Turn On Logging, and Turn Off Logging.
  • Policy Table: Displays the rule names and their details.
  • Edit button: Modifies an existing firewall rule in the table.
  • Move button: Changes the priority order of the firewall rules.
  • Delete button: Removes an existing firewall rule from the table.

Actions

Each ruleset is a grouping of DCF rules with a priority that determines evaluation order.To view rulesets and the rules within a ruleset:
  1. Go to Security > Distributed Cloud Firewall > Policies.
    The Policies page appears with the Ruleset dropdown and the Policy Table.
  2. Select a ruleset from the Ruleset dropdown.
    The Policy table shows the rules in that ruleset.
  3. Optionally, use Search or Filter to find a rule within the ruleset.
Note: Save changes for the current ruleset before switching to another.

Requires Controller version 8.0 or later.
Use Manage Rulesets on the Policies page to:
  • View all rulesets and their order
  • Create rulesets
  • Edit placement and names
  • Change ruleset priority
  • Reset traffic counts for selected rulesets
  • Commit draft changes
Note: DCF rulesets require Controller version 8.0 or later.
To manage rulesets:
  1. Go to Security > Distributed Cloud Firewall > Policies.
  2. Click Manage Rulesets.
    The Manage Rulesets dialog appears.
  3. Click the edit icon to edit the ruleset change the name and placement of the ruleset.
  4. Click the move icon to change the ruleset priority.
  5. Click the reset icon to reset the traffic counts for the selected rulesets.
  6. Click Save.
  7. Repeat steps 3–6 to create additional rulesets if needed.
  8. Click Commit to commit the saved changes.
  9. Click Close.
Create a ruleset before adding rules to it. You must use Controller version 8.0 or later to use DCF rulesets.To create a ruleset:
  1. Go to Security > Distributed Cloud Firewall > Policies.
  2. Click Manage Rulesets.
    The Manage Rulesets dialog appears.
  3. Click + Ruleset.
    The Create Ruleset dialog appears.
  4. Configure Name, Place Ruleset, and Existing Ruleset (if applicable).
    Refer to the Parameter Details table.
  5. Click Save.
  6. Repeat steps 3–5 to create additional rulesets if needed.
  7. Click Close.
  8. On the Policies tab, select a ruleset from the Ruleset dropdown to add rules to it.
The new ruleset appears in the Ruleset dropdown. You can then add rules to the ruleset.

Parameter Details

To create a distributed firewall rule:
  1. Go to Security > Distributed Cloud Firewall > Policies.
  2. Click + Rule.
  3. Configure the rule parameters. Refer to the Parameter Details table.
  4. Save the rule.
The new rule appears in the Policy Table.

Parameter Details

To edit an existing firewall rule:
  1. Go to Security > Distributed Cloud Firewall > Policies.
  2. Locate the rule in the Policy table and click the Edit button.
  3. Update the desired parameters.
  4. Save your changes.
Changes take effect after saving.
To change the priority order of firewall rules:
  1. Go to Security > Distributed Cloud Firewall > Policies.
  2. Locate the rule in the Policy Table and click the Move button.
  3. Move the rule to the desired position in the priority order.
  4. Save the new order.
Rule priority determines the order in which rules are evaluated.
To delete a firewall rule:
  1. Go to Security > Distributed Cloud Firewall > Policies.
  2. Locate the rule in the Policy Table and click the Delete button.
  3. Confirm the deletion.
The rule is removed from the Policy Table.
To reset traffic count, turn enforcement on or off, or manage logging for a rule:
  1. Go to Security > Distributed Cloud Firewall > Policies.
  2. Locate the rule in the Policy Table and click the Actions button.
  3. Select Reset Traffic Count, Turn On Enforcement, Turn Off Enforcement, Turn On Logging, or Turn Off Logging as needed.
The selected action is applied to the rule.