Add Access rules for block listing

Access rules define which connections are checked against the block list.

By default, Engines do not enforce the block list. To enforce the block list, you must define the points at which the block list is checked.

TYou can optionally add more Apply Block list rules with different matching criteria at different points in the policy.

Steps

  1. Open the Engine, or Layer 2 Interface Policy for editing.
    Block list enforcement for Virtual Engines is configured in the Engine Policy is used on the Virtual Engine.
  2. On the IPv4 Access or IPv6 Access tab, define which Sources, Destinations, and Services are compared with the block list.
  3. Right-click the Action cell and select Apply Block list.
  4. (Optional) Restrict which Engines and servers are allowed to send block list requests.
    1. Right-click the Action cell and select Edit Options.
    2. On the Block listing tab, select Restricted for the Allowed Block listers for This Rule setting.
    3. From the Available Block listers list, select the elements that you want to add to the Allowed Block listers list and click Add.
      Add the SMCaaS alias elements to allow manual block listing through the SMCaaS Application. Add the SMCaaS alias elements to allow it to relay block listing requests from other Engines.
    4. Click OK.
    Note: By default, Engines are allowed to add entries directly to their own block lists for traffic they inspect.
  5. Install the policy on the Engine to activate the changes.

Next steps

No further configuration is needed if you want to block list connections manually.