Applies To:
Show VersionsBIG-IQ Centralized Management
- 5.2.0
About firewall policies
A firewall policy is a set of rules, or rule lists, or both. BIG-IP® network firewalls use policies to specify traffic-handling actions and to define the parameters for filtering network traffic. You can assign rule lists, or a policy to a firewall. Policies facilitate the assigning of a common collection of rules consistently across multiple firewalls.
The network software compares IP packets to the criteria specified in policies. If a packet matches the criteria, then the system takes the action specified by the policy. If a packet does not match any rule in the policy, the software accepts the packet or passes it to the next policy, rule, or rule list.
In Network Security, the Policies list displays the policies available for assignment to firewalls.
You can configure firewall policies as enforced or staged:
- An enforced policy refers to a
policy whose actions are executed. Actions include: accept, accept decisively, drop, and
reject.
You are restricted to assigning a single, enforced policy on any specific firewall.
- A staged policy refers to a
policy that is evaluated but policy actions are not enforced. All activity is logged.
You are restricted to assigning a single, staged policy on any specific firewall. You can have rule lists assigned to a firewall (in the enforced area) and have a configured staged policy on that firewall. You cannot have rule lists in the staged area.
You can stage a firewall policy first and then examine logs to determine how the policy has affected traffic. Then you can determine the timing for turning the policy from staged to enforced.
Firewall policies can contain any combination of rules and rule lists. Policies cannot contain other policies. You can re-order rules within a policy.
Filtering policies
To filter the system interface to display only those objects related to a selected policy, hover over the policy name, right-click and then click Filter 'related to'. The interface is filtered and a count appears to the right of each object type. The frame to the right provides its own filter field where you can enter text and click on the filter icon to constrain the display to those items that match the filter.
Creating firewall policies
Managing firewall policies
To fine tune your network firewalls, you can edit policies, create or edit rules, and add rule lists. You can also reorder rules in firewall policies. You cannot edit rule lists or reorder rules within rule lists.
Cloning firewall policies
Users with the roles of Network_Security_View or Network_Security_Deploy cannot clone policies.
Reordering rules in firewall policies
Deleting firewall policies
You can remove obsolete firewall policies to keep network firewalls up-to-date.
If a firewall policy is in use, you cannot remove it.
To see where a firewall policy is used, right click the firewall policy name and click Filter 'related to' . The BIG-IQ system displays a count of where the policy is used in the list to the left.
- Click Policy Editor.
- On the left, click Firewall Policies to see the list of firewall policies.
- Select the firewall policy to be deleted using the check box to the left of the firewall policy.
- Click Delete and then confirm the permanent removal in the popup dialog box.