- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- R80.10 Application Blade
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
R80.10 Application Blade
Hi All
I have recently updated my SC to R80.10 and I have 5 Gateways on R77.30 and all of these use the Application and Control Blade. I have a policy under each FW policy and use the install on as the relevant gateway.
I am now going to review these rules and was wondering if I need to have 5 seperate policies still or can I have 1 policy, and then under the Install On just select all my gateways?
Thanks
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You can share your Application Control layer across all policies. This is actually recommended. You can use the Policy Targets as demo'd by Dameon's excellent video.
This is a Management-only feature, no need to upgrade an R7x gateway for that.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I've got the same setup except all runs R80.10 and segregated all this with new features like layers and parent rules from VSX MDS. In your case it would be wise to compare all those policies and unite them (consolidate them) in one global APP policy? If not possible think about APP per SG but making more out of the new layers on R80.10.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes, you can install one policy to multiple gateways and you can use the install-on field in the way you describe.
What I would also do is to set the installation target for a given policy to specific gateways.
This is a good best practice to ensure you don't accidentally install the wrong policy on the wrong gateway.
I created a brief video explaining how to do this.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You can share your Application Control layer across all policies. This is actually recommended. You can use the Policy Targets as demo'd by Dameon's excellent video.
This is a Management-only feature, no need to upgrade an R7x gateway for that.
