Create a Engine Policy

After creating the customized Engine Template Policy, create a Engine Policy based on the template.

For more information, see the Considerations for designing Access rules topic in the Access rules chapter and the Creating and managing policy elements chapter in the Forcepoint Network Security Platform Product Guide.

Access rules affect all network interfaces, unless the source interface is specified. For more information about using Zone elements, see the Using Zone elements for interface matching in Access rules topic in the Access rules chapter in the Forcepoint Network Security Platform Product Guide.

For more details about the product and how to configure features, click Help or press F1.

Steps

  1. Create a Engine Policy that uses the Engine cPP Template.
  2. To add an Access rule, right-click the IPv4 Insert Point or IPv6 Insert Point, then select Add Rule.
    Tip: You can right-click the ID cell to add more Access rules and to move Access rules up and down in the Policy.
  3. To fill in the cell values for an Access rule, you can do the following:
    • Drag elements to the cell from the resource pane on the left.
    • Click the cell, then start typing to activate the look-ahead search.
    • Double-click the cell to open a dialog box where you can configure the settings.
  4. To configure the logging for a rule, double-click the Logging cell, then configure the settings.

    Select Override Settings Inherited from Continue Rule(s), then set the Log Level to Essential.

    Note: Packets that are automatically rejected are not logged by default. To enable the logging of all packets, right-click the Security Engine, select Options > Diagnostics, then under Packet Processing, select Packet Filtering. Click OK to close the dialog box.