Skip to main content

Security Policy

Policy combines one or more Security policy definitions to create a Policy based on use-case. These policies can then be attached to device templates.

Diagram

Classes

security_policies (sdwan)

NameTypeConstraintMandatoryDefault Value
feature_policiesList[feature_policies]No

feature_policies (sdwan.security_policies)

NameTypeConstraintMandatoryDefault Value
nameStringRegex: ^[A-Za-z0-9\-_]{1,32}$Yes
descriptionStringYes
use_caseChoicecustom, compliance, guest_access, direct_cloud_access, direct_internet_access, app_qoeYes
firewall_policiesListString[Regex: ^[A-Za-z0-9\-_]{1,32}$]No
intrusion_prevention_policyStringRegex: ^[A-Za-z0-9\-_]{1,32}$No
additional_settingsClass[additional_settings]No

additional_settings (sdwan.security_policies.feature_policies)

NameTypeConstraintMandatoryDefault Value
firewallClass[firewall]No
ips_url_ampClass[ips_url_amp]No

firewall (sdwan.security_policies.feature_policies.additional_settings)

NameTypeConstraintMandatoryDefault Value
direct_internet_applicationsBooleantrue, falseNo
tcp_syn_flood_limitIntegermin: 1, max: 4294967295No
high_speed_loggingClass[high_speed_logging]No
audit_trailBooleantrue, falseNo
match_stats_per_filterBooleantrue, falseNo

ips_url_amp (sdwan.security_policies.feature_policies.additional_settings)

NameTypeConstraintMandatoryDefault Value
external_syslog_serverClass[external_syslog_server]Yes
failure_modeChoiceopen, closeYes

high_speed_logging (sdwan.security_policies.feature_policies.additional_settings.firewall)

NameTypeConstraintMandatoryDefault Value
vpn_idIntegermin: 0, max: 65530Yes
server_ipIPYes
server_portIntegermin: 0, max: 65535Yes

external_syslog_server (sdwan.security_policies.feature_policies.additional_settings.ips_url_amp)

NameTypeConstraintMandatoryDefault Value
vpn_idIntegermin: 0, max: 65530Yes
server_ipIPYes

Examples

sdwan:
security_policies:
feature_policies:
- name: Security_policy_generic
description: Security Policy Generic
use_case: custom
firewall_policies:
- allow_http_internal
- allow_critical_apps
intrusion_prevention_policy: inspect_web_apps
additional_settings:
firewall:
direct_internet_applications: true
tcp_syn_flood_limit: 1239
high_speed_logging:
vpn_id: 1
server_ip: 1.1.1.1
server_port: 2055
audit_trail: true
match_stats_per_filter: true
ips_url_amp:
external_syslog_server:
vpn_id: 2
server_ip: 2.2.2.2
failure_mode: open