Hi CheckMates,
I am curious about the policy enforcement order of the Legacy MAB policy. I understand that with the Unified Policy, it's possible to create Inline/Ordered layers and implement the MAB into that. But when is the Legacy MAB policy enforced? Before or after the Access rules?
I noticed that some MAB rules (in the SmartDashboard) allow a SNX user to a certain resource, but since there isn't a corresponding rule in the Access Rulebase (FW Blade) the traffic is dropped. The logs show a similar story, an "Accept" of the packet hitting the MAB blade, immediately followed by a default drop by the FW blade.
Is it necessary to replicate all rules from the Legacy MAB into the Access policy as well?
Thanks,
R81.10 Take130.