- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- Re: Exclude a policyset from Compliance Blade
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Exclude a policyset from Compliance Blade
Hi
Is it possible to exclude a policy set from the compliance blade, it is the default VSX cluster policy set I want to exclude from compliance blade.
- Tags:
- r80.10 compliance
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Do you want to exclude the policy installed to VS0?
You would add VS0 here:
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes i did exclude VS0, but the policy set for VS0 is still listed in the URL filtering rules and Application Control rules.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Will look into this.
Tomer Sole any thoughts?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You have to disable the relevant Best Practices for VS0.
Find the appropriate Best Practices and uncheck the VS0 object.
An example from Demo Mode (admittedly not using VSX objects, but same concept applies).
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
It is the policy set that is testet, and not the gateway where it is installed on.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Can't you just uncheck all the gateways where this option is irrelevant?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The option is not connected to ag Gateway only to a Rulebase
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi! I had the same question about excluding a policy. After adding a SG to Inactive Gateways in the Inactive Objects menu (button), all the requirements will not be checked against this gateway, so the Compliance results will change to include only the applicable policy/policies for the gateways that are active.
I suppose it is good that we still have the requirements listed for the other policies and their rules, so we can prepare a policy and have it checked before we apply it to a SG.
