Using Advance Policy to Create VPN Policies
Why Migrate from Classic Policy to Advance Policy?
-
Ability to access the body of the messages.
-
Supports many other protocols.
-
Accesses many other features of the system.
-
Has more number of basic functions, operators, and data types.
-
Caters to the parsing of HTML, JSON, and XML files.
-
Facilitates fast parallel multi-string matching (
patsets, and so forth).
-
Session Policy
-
Authorization Policy
-
Traffic Policy
-
Tunnel Policy
-
Audit Policy
Pre-authentication EPA using Advanced EPA
Post authentication EPA using Advanced EPA
Pre-authentication and post-authentication EPA using Advanced policies
Periodic EPA scan as a factor in nFactor authentication
-
Classic and Advance policies of the same type (for example, Session policy) cannot be bound to the same entity/bind point.
-
Priority is mandatory for all PI policies.
-
Advance Policy for the VPN can be bound to all bind points.
-
Advance Policy with the same priority can be bound to a single bind point.
-
If none of the configured authorization policies get selected, then the global authorization action configured in the VPN parameter is applied.
-
In authorization policy, the authorization action is not reversed if the authorization rule fails.
| Classic Policy expressions | Advance Policy expressions |
|---|---|
| ns_true | true |
| ns_false | false |
| REQ.HTTP | HTTP.REQ |
| RES.HTTP | HTTP.RES |
| HEADER "foo" | HEADER("foo") |
| CONTAINS "bar" | .CONTAINS("bar") [Note use of “..”] |
| REQ.IP | CLIENT.IP |
| RES.IP | SERVER.IP |
| SOURCEIP | SRC |
| DESTIP | DST |
| REQ.TCP | CLIENT.TCP |
| RES.TCP | SERVER.TCP |
| SOURCEPORT | SRCPORT |
| DESTPORT | DSTPORT |
| STATUSCODE | STATUS |
| REQ.SSL.CLIENT.CERT | CLIENT.SSL.CLIENT_CERT |