Applies To:
Show Versions
BIG-IQ Centralized Management
- 5.0.0
About service and timer policies
A service policy allows you to associate network idle timers on firewall contexts and rules.
You can discover a service policy on a BIG-IP® device version 12.0 or later, or create one on a BIG-IQ® system using the Network Security Policy Editor and then deploy it to a BIG-IP device version 12.0 or later.
A service policy contains a timer policy, also known as a firewall idle timer, which contains timer rules that can be associated with firewall contexts and rules. A service policy can be applied to the global, self IP address, or route domain context. It can also be added to a rule in a rule list, or a rule on a security policy. Service policies and timer policies are created separately, and then the timer policies are added to service policies.
Creating a timer policy
Creating a service policy
Applying a service policy to a firewall rule
- Log in to the BIG-IQ® system with your user name and password.
- At the top left of the screen, select Network Security from the BIG-IQ menu.
- Click Policy Editor.
-
Display the list of rules from a rule list or from a firewall security policy
in the policy editor.
Option Description If the rule is in a rule list: On the left, click Rule Lists, and then click the name of the rule list containing the rule. The rules are listed on the Rules tab. If the rule is associated with a policy: On the left, click Firewall Policies, and then click the name of the policy containing the rule. The rules are listed on the Rules & Rule Lists tab. - To make it editable, click the name of the rule to which you want to add the service policy.
-
Add the service policy to the rule.
Option Description Add the service policy by typing. Type the name of the service policy in the Service Policy column for the rule. The system completes name of the service policy once you begin typing the name. Add the service policy by drag and drop. In the Shared Resources area, select Service Policies, and then drag the service policy from that list and drop it into the Service Policy column for the rule. -
Save your changes in one of two ways:
- Click Save to save your changes and still be able to edit.
- Click Close to save your changes and stop editing.
Applying a service policy to a global context
Applying a service policy to a route domain context
Applying a service policy to a self IP address context
Deleting a timer policy
- Log in to the BIG-IQ® system with your user name and password.
- At the top left of the screen, select Network Security from the BIG-IQ menu.
- Click Policy Editor, and then in the list on the left, click Timer Policies.
- Select the check box to the left of any timer policy that you want to remove.
- Click Delete.
- Confirm that you want to remove the timer policy by clicking Delete in the confirmation dialog box.
Deleting a service policy
- Log in to the BIG-IQ® system with your user name and password.
- At the top left of the screen, select Network Security from the BIG-IQ menu.
- Click Policy Editor, and then in the list on the left click Service Policies.
- Select the check box to the left of any service policy you want to remove.
- Click Delete.
- Confirm that you want to remove the service policy by clicking Delete in the confirmation dialog box.