Network Security
Create a Security Profile Group (Strata Cloud Manager)
Table of Contents
Expand All
|
Collapse All
Network Security Docs
Create a Security Profile Group (Strata Cloud Manager)
Create a security profile group and add it to a Security policy.
In Strata Cloud Manager, a Security profile is only active when these two things are
in place:
- The Security profile is in a profile groupA profile group is a set of profiles—it can contain one profile from each profile type.
- A Security rule is referencing the profile groupWhen a Security rule is referencing a profile group, you can make updates to the individual profiles and the group without editing the Security rule. The Security rule automatically enforces your changes, without requiring you to make a policy commit.To get started, you’ll need to:
- Add a profile groupWhen adding a Security Profile Group to your configuration, begin by providing a descriptive name and optional description to identify the purpose and functionality of the group.
- Choose your Security ProfilesSelect the security profiles you wish to include within the group. These profiles can encompass various security aspects such as antivirus, antispyware, vulnerability protection, URL Filtering, and more. Customize each selected profile based on specific security rules and threat prevention needs.After configuring the profiles, associate the profile group with security rules to ensure consistent and comprehensive threat prevention. Implement this association by editing existing security rules or creating new ones, referencing the Security Profile Group accordingly.
- Review your Security Profile GroupRegularly reviewing and updating your Security Profile Groups is crucial to adapt to evolving threats and security requirements. This iterative process involves fine-tuning profile settings and incorporating new threat intelligence to optimize security efficacy. By effectively utilizing security profile groups, you can streamline security policy management, achieve granular threat prevention, and fortify your network against a wide array of cyberthreats.
Use the following steps to create a security profile group and add it to a Security policy.
- Create a security profile group.If you name the groupdefault, it'll be automatically attached to any new rules you create. This is a time saver if you have a preferred set of security profiles that you want to make sure get attached to every new rule.
- SelectandManageConfigurationNGFW andPrisma AccessSecurity ServicesProfile GroupsAdd Profile Group.
- Give the profile group a descriptiveName, for example, Threats.
- Add existing profiles to the group.
- SelectSaveto save the profile group.
- Add your security profile group to a Security policy.
- SelectandManageConfigurationNGFW andPrisma AccessSecurity ServicesSecurity PolicyAdd Ruleor modify a security security rule.
- In theProfile Groupdrop-down in theActionstab, select the group you created (for example, select the best-practice group):
- SelectSaveto save the security rule.
- SelectPush Configto push your configuration changes to your network.
Set Up or Override a Default Security Profile Group
A Security Profile Group streamlines the
management and application of security settings, allowing you to apply a set of
predefined profiles to traffic based on their security
requirements.
Additionally, you can set up a default Security Profile
Group to be used in new security rules, or to override an existing
default group. When you create a new Security policy, the default profile group
is automatically selected as the policy’s profile settings, and traffic matching
the policy are checked according to the settings defined in the profile group
(you can choose to manually select different profile settings if desired).
Use the
following options to set up a default Security Profile Group or to override your
default settings.
- Set up a default security profile group.
- Selectand add a new security profile group or modify an existing security profile group.ManageConfigurationNGFW andPrisma AccessSecurity ServicesProfile Groups
- Namethe security profile groupdefault:
- SelectSaveandPush Config.
- Confirm that the default security profile group is included in new security rules by default:
- SelectandManageConfigurationNGFW andPrisma AccessSecurity ServicesSecurity PolicyAdd Rule.
- Select theActionstab and view theProfile Settingfields:The new Security policy has the defaultProfile Groupselected.
- Override a default security profile group.If you have an existing default security profile group, and you do not want that set of profiles to be attached to a new security rule, you can select a different Profile Group.