Managing prerules and postrules
Copyright © 2010, Juniper Networks, Inc.
Install-On Column for prerules and postrules
In 2007.2 NSM Policy Manager, the Install-On column is the mechanism to specify which
devices use a particular rule. While configuring a pre/post rule in Central Manager, rule
application is applied at regional server level. The Install-On column, in this case, accepts
only the Regional Server object or ANY as legal entries. When a Central Manager pushes
a pre/post rule to a regional server, content in this column specifies which rule is pushed
to which regional server.
To manage post/pre rules, Central Manager administrators can:
Add prerules and postrules
Push prerules and postrules to Regional Server
Modify prerules and postrules
Delete prerules and postrules
Add prerules and postrules
This procedure assumes that a Central Manager administrator is logged onto a Central
Manager client.
To add a pre/post rule:
In the main navigation tree, select Policy Manager > Central Manager Policies.
1.
Select either Central Manager Pre Rules or Central Manager Post Rules.
2.
Click the Add icon in the toolbar and select Add Rule.
3.
Select a regional server object for the rule's Install On column, as necessary.
4.
Prerules and postrules can be added at the subdomain, global, or central manager
level. Prerules and postrules use the precedence of central manager, global and then
subdomain when applied to a policy.
Push prerules and postrules to Regional Server
This procedure assumes that a Central Manager administrator is logged onto a Central
Manager client, and a pre/post rule has been added.
To push a pre/post rule:
In the main navigation tree, select Policy Manager > Central Manager Policies.
1.
Select either Central Manager Pre Rules or Central Manager Post Rules.
2.
Select Tools > Update Regional Servers.
3.
Select the regional servers to which you want to push prerules and postrules.
4.
Central Manager Administrator monitors progress from the Job Manager.
Chapter 9: Configuring Security Policies
521
Need help?
Do you have a question about the NETWORK AND SECURITY MANAGER 2010.3 - ADMINISTRATION GUIDE REV1 and is the answer not in the manual?
Questions and answers