Adding or editing Policy Server instances

Use the Add Policy Server or Edit Policy Server page to associate a new Policy Server instance with the Forcepoint Security Manager, or to update configuration information for an existing Policy Server.

Steps

  1. Enter or edit the IP address or name and communication Port for the Policy Server instance. The default port is 55806.
  2. Enter or update the Description of the selected Policy Server instance. You cannot change the description for the base Policy Server.
  3. Indicate whether this is a Primary or Secondary Policy Server.
    • A primary Policy Server has a different subscription key than other Policy Server instances associated with the Security Manager.
    • A secondary Policy Server uses the same subscription key as another Policy Server that has already been associated with the Security Manager.
  4. If this is a secondary Policy Server:
    1. Select the IP address of the primary Policy Server from which the secondary should get its key.
    2. Indicate whether this secondary should inherit its Directory Services settings from the primary Policy Server.

      These are the settings (configured on the Settings > General > Directory Services page) that User Service uses to connect to a directory and retrieve user and group information.

    3. Click OK to return to the Policy Servers page, then click OK again on the Policy Servers page to cache your changes. Changes are not implemented until you click Save and Deploy.

    Note that after adding a secondary Policy Server, you may have to log off of the Security Manager and log on again before you can use the Policy Server Switch button to connect to the new Policy Server instance.

  5. If this is a primary Policy Server, indicate whether to Use the current subscription key registered to the new instance or Enter a subscription key.
    • If you are editing an existing entry, the current subscription key and subscription type are displayed below the radio buttons.
    • Click Verify Policy Server to make sure that the Security Manager can communicate with the new Policy Server. If you have selected “Use the current subscription key,” and the connection is successful, the subscription key is displayed.
    • If you are not sure whether the new Policy Server instance already has a key registered, you can either select the option to enter the key manually, or click Verify Policy Server to see if the Security Manager finds an existing key for the instance.
  6. Click OK to return to the Policy Servers page. You must click OK again to cache your changes. Changes are not implemented until you click Save and Deploy.