Skip to content

Security Advanced Inspection Profile

Configure Security Advanced Inspection Profile.

Diagram

policy_object_profile (sdwan.feature_profiles)

Section titled “policy_object_profile (sdwan.feature_profiles)”
NameTypeConstraintMandatoryDefault Value
security_advanced_inspection_profilesList[security_advanced_inspection_profiles]No

security_advanced_inspection_profiles (sdwan.feature_profiles.policy_object_profile)

Section titled “security_advanced_inspection_profiles (sdwan.feature_profiles.policy_object_profile)”
NameTypeConstraintMandatoryDefault Value
nameStringRegex: ^[^&<>! "]{1,32}$Yes
descriptionStringNo
advanced_malware_protectionStringRegex: ^[^&<>! "]{1,32}$No
intrusion_preventionStringRegex: ^[^&<>! "]{1,32}$No
tls_actionChoicedecrypt, never_decrypt, skip_decryptYes
url_filteringStringRegex: ^[^&<>! "]{1,32}$No

Example-1: This example demonstrates how to configure a Security Advanced Inspection Profile with intrusion_prevention and tls_action.

sdwan:
feature_profiles:
policy_object_profile:
security_advanced_inspection_profiles:
- name: advanced_inspection_basic
intrusion_prevention: intrusion_prevention_basic
tls_action: skip_decrypt