Cisco Cisco Firepower Management Center 4000

Seite von 1844
 
14-14
FireSIGHT System User Guide
 
Chapter 14      Understanding and Writing Access Control Rules 
  Understanding Rule Conditions and Condition Mechanics
Your rule is added and the policy Edit page appears.
Searching Condition Lists
License: 
Any
You can filter a list of available access control rule conditions and condition categories to limit the 
number of items displayed in the list. The list updates as you type to display matching items.
Optionally, you can search on object names and on the values configured for objects. For example, if you 
have an individual network object named Texas Office with the configured value 192.168.3.0/24, and the 
object is included in the group object US Offices, you can display both objects by typing a partial or 
complete search string such as 
Tex
, or by typing a value such as 3
The following basic procedure explains how to filter a list in a new rule. See 
 for complete instructions on adding and modifying rules.
To search a list of available conditions or condition categories:
Access: 
Admin/Access Admin/Network Admin
Step 1
Select 
Policies > Access Control
.
The Access Control page appears.
Step 2
Click the edit icon (
) next to the access control policy you want to modify.
The policy Edit page appears.
Step 3
Click 
Add Rule
.
The Add Rule page appears.
Step 4
To search a list, click inside the search field to clear the prompt, then type a search string.
The list updates as you type to display matching items and a clear list icon (
) appears in the search 
field. The list updates and no items are listed when none match the search string.
Step 5
Optionally, click the reload icon (
) above the search field or click the clear icon (
) in the search 
field to clear the search string.
The complete list appears.
Step 6
Click 
Add
 to save your configuration.
Your rule is added and the policy Edit page appears.
Adding Literal Conditions
License: 
Any
You can add a literal value to the list of selected conditions for the following condition types:
  •
Networks
  •
VLAN Tags
  •
Ports