Policy hierarchies
The policy structure is a hierarchy based on templates.
The structure allows you to:
- Reuse rules without duplicating them.
- Assign and enforce editing rights of a single policy to administrators.
- Reduce the resource consumption of the Engines.
- Make policies easier to read.
The template and policy hierarchy is flattened when the Policy is transferred to the Engines. The policy looks the same to the Engines regardless of how it is organized on the SMCaaS (as long as the rules are in the same order). You can also create sections of conditional IPv4 Access rules that you can insert into the other policy elements. The Engine can skip the processing of a conditional block of rules based on whether certain common matching criteria is found in the packet being examined.
If your environment is simple and you do not need the benefits outlined here, you can create a simple policy hierarchy. You can, for example, start with one Engine Policy built on the provided Firewall Template. The same Engine Policy can be used on more than one Engine.