Use Dynamic Address Groups in Policy (Strata Cloud Manager)
Focus
Focus
Network Security

Use Dynamic Address Groups in Policy (Strata Cloud Manager)

Table of Contents


Use Dynamic Address Groups in Policy (Strata Cloud Manager)

Create security rules that automatically adapts to changes.
The following example shows how Dynamic Address Groups can simplify network security enforcement. The example workflow shows how to:
  • Create Dynamic Address Groups and define the tags to filter.
  • Use Dynamic Address Groups in policy.
  1. Create Dynamic Address Groups.
    View the tutorial to see a big picture view of the feature.
    1. Select ManageNGFW and Prisma AccessObjectsAddressAddress Groups.
    2. Select Add Address Group and enter a Name and a Description for the address group.
    3. Select Type as Dynamic.
    4. Define the match criteria. You can select dynamic and static tags as the match criteria to populate the members of the group. Click Add Match Criteria, and select the And or Or operator and select the attributes that you would like to filter for or match against, then select Save. Negation isn’t supported.
    5. Click Commit.
  2. Use Dynamic Address Groups in policy.
    View the tutorial.
    1. Select ManageNGFW and Prisma AccessSecurity ServicesSecurity Policy.
    2. Select Add Rule and enter a Name and a Description for the policy.
    3. Add the Source Zone to specify the zone from which the traffic originates.
    4. Add the Destination Zone at which the traffic is terminating.
    5. For the Destination Address, select the Dynamic Address Group you just created.
    6. Specify the action— Allow or Deny—for the traffic, and optionally attach the default security profiles to the rule.
    7. Repeats steps 1 through 6 to create another security rule.
    8. Select Push Config.