Here you go - the FLAT rulebase:
1. create a policy package:
mgmt_cli add package name "my_policy" threat-prevention "false" -s id.txt
2. add the rules to the NETWORK (!!!) layer:
mgmt_cli add access-rule layer "my_policy Network" source "any" destination "h1" service "http" action "accept" track-settings.type "Log" position "1" name "rule1" -s id.txt
3. publish:
mgmt_cli -s id.txt publish
This is the result in SmartConsole:
data:image/s3,"s3://crabby-images/bca58/bca58f55b4193cdf90cf02c044408e526cfc8fd1" alt=""
data:image/s3,"s3://crabby-images/192bc/192bc9bb76df0412ce63460e69f90c1c6ef12713" alt=""
Please pay attention that the Cleanup Rule is automatically created along with the package creation.
You can also add sections, like in R77:
mgmt_cli add access-section layer "my_policy Network" position 1 name "New Section 1" -s id.txt
mgmt_cli -s id.txt publish
data:image/s3,"s3://crabby-images/0e829/0e829bdd7269bc856433c1325596ee1187cd5803" alt=""
Hope this can assist.
Robert.