Cloud Edge Secure Access Getting Started Guide

Network Traffic Control

This article describes why and how you can protect and limit access to your resource(s) by defining policies and rules based on user groups, origin and/or destination IPs, ports, and/or network protocols.

It isn’t just about controlling your inbound or outbound network traffic but being able to manage your entire network traffic based on user-based and network-based Rules that define which applications, resources, regions, and data-centers can be accessed through encrypted tunnels.

By enabling Network Traffic Control you'll secure and control the entire traffic on one unified Software-Defined Perimeter (SDP).

For example, you can allow Groups of your users (each with their own policies and rules) to specific parts of a certain network, only using a specific protocol and only when coming from your internal subnet IP range.

Activate Network Traffic Control

You can activate a set of Rules and Policies per SASE Network. In case you have more than one Network in your tenant you can activate the Network Traffic Control to some or all of your Networks.

In order to activate Network Traffic Control on an existing Network:

  1. Navigate to Network > Network Traffic Control.
  2. In the Network Traffic Control screen, you will see all the Networks that you've created in your tenant.
  3. Select the appropriate Network, set the Network's Default Action, and turn on the toggle.

    The Default Action defines how to treat connections and traffic which doesn't have a specific Network Policy Rule.
    Allow - All traffic will be allowed to all connected resources unless a specific Rule defines a different action.
    Deny - All traffic will be blocked to all connected resources unless a specific Rule defines a different action.

  4. Click on Apply Changes.

Add a Rule

The Network Traffic Control is combined out of a list of Rules that defines the access and traffic routing policies. You can create multiple rules that will apply specific policies for specific User Groups, Resources, and Protocols as well as wide Policies that will be applied to the entire Network traffic (i.e block all traffic on a specific port).

To create a new Rule:

  1. Navigate to Networks > Network Traffic Control.
  2. Click on (+) Add New Rule.
  3. Select the Network where the Rule should be added.
  4. Provide an indicative Name.
  5. Select the Action type.
  6. Add Source and Destination Objects.

    The Source and Destination define the conditions that have to be met in order for the Action to be applied to the traffic.
    There are four types of Objects that can be used in the Source and Destination conditions:
    Any - All traffic on all protocols and ports coming from any of the End-Points or encrypted tunnels.
    Groups or Members - All traffic routed from/to a specific Member or Users Group.
    Addresses - Traffic routed from/to an IP Address, Subnet, or List of IPs.
    Services - Traffic routed on a specific Protocol or Ports.

  7. Drag the new Rule to the right Priority.

    Rules are applied based on the priority of the Rule. Should different rules overlap, the rule with the Lower Priority Number will take precedence (i.e. Rule with Priority #2 will take precedence over Rule with Priority #5).

  8. Click on Apply Changes.

Create Objects

When configuring Firewall rules you'll be defining Rules that are based on Objects and User Groups.

  • The Objects will be used in order to specify IP Addresses, Subnets, Network Protocols, and Ports.
  • The User Groups will be used in order to manage access of users to/from Objects and can be managed via the Groups tab.

Addresses

The Addresses Object allows you to define subnets, IP lists, and specific IP addresses that can be used in the Network Traffic Control rules.

To create a new Address Object:

  1. Navigate to Objects > Addresses.
  2. Click on (+) Add Address.
  3. Provide an indicative Name and Description.
  4. Select the type of Object (IP, Subnet, or List) and provide the values.
  5. Click on Add Address.

Services

The Services Object allows you to define Network Protocols, Port lists, and specific Ports that can be used in the Network Traffic Control rules.

To create a new Services Object:

  1. Navigate to Objects > Services.
  2. Click on (+) Add Service.
  3. Provide an indicative Name and Description.
  4. Select the Protocol (Port, Range, or List) and provide the values.
  5. Click on Add Service.


Was This Article Helpful?

Help us to improve our support portal

Techdocs Article Helpful form

  • Hidden
  • Hidden

Techdocs Article NOT Helpful form

  • Still can't find what you're looking for? Try our knowledge base or ask our community for more help.
  • Hidden
  • Hidden