Skip to main content
This section provides the purpose, elements, and actions performed on the Distributed Cloud Firewall pages.

Purpose

The Policies page creates and manages distributed firewall policies for securing traffic across the multi-cloud environments.

Elements

Distributed Cloud Firewall: Policies
  • + Rule button: Starts the workflow to create a new firewall rule.
  • Manage Rulesets: Opens the dialog to create, edit, or manage rulesets (groupings of rules). Create rulesets before adding rules to them (Controller 8.0 or later).
  • Actions button: Provides options to Reset Traffic Count, Turn On Enforcement, Turn Off Enforcement, Turn On Logging, and Turn Off Logging.
  • Policy Table: Displays the rule names and their details.
  • Edit button: Modifies an existing firewall rule in the table.
  • Move button: Changes the priority order of the firewall rules.
  • Delete button: Removes an existing firewall rule from the table.

Actions

Each ruleset is a grouping of DCF rules with a priority that determines evaluation order.To view rulesets and the rules within a ruleset:
  1. Go to Security > Distributed Cloud Firewall > Policies.
    The Policies page appears with the ruleset list and the Policy Table.
  2. To view the full list of rulesets and their order, click Manage Rulesets.
    The Manage Rulesets dialog displays all rulesets and their priority order.
  3. Click Close to return to the Policies tab.
  4. On the Policies tab, select a ruleset from the ruleset list (dropdown or selector).
    The Policy Table shows the rules in that ruleset.
  5. Optionally, use Search or Filter to find a rule within the ruleset.
Note: Save changes for the current ruleset before switching to another.

Requires Controller version 8.0 or later.
Create a ruleset before adding rules to it. You must use Controller version 8.0 or later to use DCF rulesets.To create a ruleset:
  1. Go to Security > Distributed Cloud Firewall > Policies.
  2. Click Manage Rulesets.
    The Manage Rulesets dialog appears.
  3. Click + Ruleset.
    The Create Ruleset dialog appears.
  4. Configure Name, Place Ruleset, and Existing Ruleset (if applicable).
    Refer to the Parameter Details table.
  5. Click Save.
  6. Repeat steps 3–5 to create additional rulesets if needed.
  7. Click Close.
  8. On the Policies tab, select a ruleset from the Ruleset dropdown to add rules to it.
The new ruleset appears in the Ruleset dropdown. You can then add rules to the ruleset.

Parameter Details

Sl. No.CoPilot Parameter NameDescription
1NameEnter a name for the ruleset.
2Place RulesetSelect where to place the ruleset: above or below an existing ruleset, or at the top or bottom of the ruleset list.
3Existing RulesetIf you select Above or Below in Place Ruleset, select the existing ruleset from this list.
To create a distributed firewall rule:
  1. Go to Security > Distributed Cloud Firewall > Policies.
  2. Click + Rule.
  3. Configure the rule parameters. Refer to the Parameter Details table.
  4. Save the rule.
The new rule appears in the Policy Table.

Parameter Details

Sl. No.CoPilot parameter nameDescription
1PriorityShows the order in which the rule applies.
2NameShows the name of the firewall rule.
3Source GroupsShows the source VPCs or network groups.
4Destination GroupsShows the destination network or internet target.
5WebGroupShows the web group linked to the rule.
6ProtocolShows the traffic type such as TCP, UDP, ICMP, or Any.
7PortsShows the port or port range used by the rule.
Rule Behavior
8ActionShows whether the rule permits or denies traffic.
9SG orchestrationShows whether security group sync is enabled.
10DecryptionShows whether traffic decryption is enabled.
11Intrusion analysisShows whether traffic inspection is enabled.
12LoggingShows whether traffic logs are enabled.
To edit an existing firewall rule:
  1. Go to Security > Distributed Cloud Firewall > Policies.
  2. Locate the rule in the Policy table and click the Edit button.
  3. Update the desired parameters.
  4. Save your changes.
Changes take effect after saving.
To change the priority order of firewall rules:
  1. Go to Security > Distributed Cloud Firewall > Policies.
  2. Locate the rule in the Policy Table and click the Move button.
  3. Move the rule to the desired position in the priority order.
  4. Save the new order.
Rule priority determines the order in which rules are evaluated.
To delete a firewall rule:
  1. Go to Security > Distributed Cloud Firewall > Policies.
  2. Locate the rule in the Policy Table and click the Delete button.
  3. Confirm the deletion.
The rule is removed from the Policy Table.
To reset traffic count, turn enforcement on or off, or manage logging for a rule:
  1. Go to Security > Distributed Cloud Firewall > Policies.
  2. Locate the rule in the Policy Table and click the Actions button.
  3. Select Reset Traffic Count, Turn On Enforcement, Turn Off Enforcement, Turn On Logging, or Turn Off Logging as needed.
The selected action is applied to the rule.