SonicOSX 7 Rules and Policies

Shadow

Shadow rules are provided to monitor overlapping rules on a per-rule basis. The Shadow feature displays each rule and reveals all rules that are shadowed by that rule. It also provides a list of rules that are shadowed from the rule. Shadow rules generally indicate a broader rule that matches the criteria, but it is configured above a more specific rule. You can select and view all rules and shadow data for any rule.

For example, rule traffic never matches a second rule that specifically allows say, web-browsing, because all web-browsing applications would have already been allowed by the first rule.

To monitor Shadow rules

  1. Navigate to POLICY | Rules and Policies > Shadow.

    The Shadow page appears.

  2. Search for specific rules using the Search feature.
  3. You can sort the shadowing of previously created Rules and Policies rules by Policy Type. Options include Security Policy, NAT Policy, Route Policy, Decryption Policy, and DoS Policy.
  4. You can further sort the Policy Type by first selecting the policy type, in this example, Route Policy, then using the All Rules drop-down menu, select the specific policy you would like to investigate (in the case Route Policy_4).

  5. Click the blue naming instance to view additional Route Policy Details.

  6. To generate an updated list of Shadow policies, click Generate in the top right option bar.

Was This Article Helpful?

Help us to improve our support portal

Techdocs Article Helpful form

  • Hidden
  • Hidden

Techdocs Article NOT Helpful form

  • Still can't find what you're looking for? Try our knowledge base or ask our community for more help.
  • Hidden
  • Hidden