Manual Chapter : Creating Security Policies

Applies To:

  • F5 SSL Orchestrator

    17.1.0

Creating Security Policies

To create a new security policy:

  1. Select Create New and enter a name for your policy.

  2. For L3 Inbound/Application topology, select the policy type from the Provider list.

  3. Click Add to create a new security policy rule.

  4. Select a condition from the first dropdown list for which you want to configure the rule. Specify conditions, match type (match any/match all), operators (is ) or (is not) that compares or negates the selected value, and choose the action (reject/allow/abort) for that traffic. Select a service chain and specify if SSL proxy traffic will be intercepted or bypassed. Use the + sign to add additional conditions and the x sign to remove any unwanted rule condition.

    Note: Refer the Using Conditions in Rules section for recommended tips.

  5. Select Server Certificates Status Check checkbox to add a new per-request policy agent for server certificate status and to allow administrators to select ignore/mask options and generate a blocking page for untrusted and expired server certificates.

  6. Select Proxy Connect if you want to add an upstream explicit proxy to your security rule chaining. You can add multiple proxy devices, or pool members, as necessary.

  7. Click Save Draft or Save & Next before you leave the screen.