Allowing system communications in Access rules

You must add Access rules for some types of communication between SMCaaS Application.

The necessary communications between the Engine and SMCaaS Application is allowed in the predefined Firewall Template Policy.

For example, when you have a Engine at a remote site that are managed by a SMCaaS Application behind a Engine at a central site, you must create rules in the Engine Policy at the central site to allow:
  • Management and monitoring connections to/from the remote Engine.
  • Monitoring and log browsing connections from the central site to the SMCaaS Application.
  • Any remote-site Engine connections to the SMCaaS Application at the central site.

If NAT is applied to the connections, Access rules alone are not enough. You must also create Location elements and add Contact Addresses for the elements to define which translated addresses are necessary for making contact.

There are predefined Service elements for all system communications. You can use these elements to create Access rules.