Sorry, but this comment "It should only be Drop if you're certain you have rules in both layers to allow all relevant traffic", I can't interpret it well.
My environment is Clusters in R81.10 version.
The previous administrator inherited me the solution, with "separate layers".
Maybe with an example it could be clearer.
If I have an IP 192.168.100.5 and I want to give it to consume, only "LinkedIN and Youtube", I will use "LinkedIN and Youtube".
I must have a rule, in the security layer, in this sense
SRC: 192.168.100.5
DST: ANY
SERVICE: ANY
And apart a rule in APPC/URLF, almost in the same sense, except that here I will be able to specify the applications that I want.
Is this the correct way?
In this case, the implicit rule of the APPC/URLF layer, how should it go, as ALLOW or DROP?
Thank you. 🙂