Hi there,
I wanted to start using inline layers.
I am trying to the think how I would edit my user->internet web traffic as this would be the heaviest rule in the rulebase.
I have AC/URL, CA, ThreatPrevention (AV, AB and IPS) and HTTPs inspection blades on R80.30.
I currently have several rules that apply to all my users in AC/URLF and TP.
Would I create an inline layer with Firewall enabled and then sub-layers for each of the blades above? Should I go just one deep when creating these layers or layers within layers? Most of my rules apply to all users.
I created a Content Awareness layer in my rulebase to test and although it works ok, when I try to add extra rules with source/destination Any (parent rule has all my user networks as source) the policy installation throws an error as it doesn't like Any in the source or destination on more than one rules in the layer.
Moreover, I noted that the packets are inspected by my ordered layers irrespective of the fact that I have a catch all rule in the inline layer. Is this expected?
A.