After the Symantec Firewall Service and Service
Center Data Center IPSEC router or Cloud Connector are configured,
the next step is to steer branch application traffic to the Firewall
Services.
Some of the most common examples of how a traffic
policy can be configured per application are:
Send
all Internet-bound traffic from a set of branches to the Symantec
Firewall Service (Blanket Suspect list).
Send all Internet-bound traffic from a set of branches to
the Symantec Firewall service except for specific known applications.
(Suspect list-Allow list).
Send all Internet traffic direct to the Internet except for
certain applications that need additional inspection or security.
(Allow list-Suspect list).
The Prisma SD-WAN Secure
Application Fabric enables granular controls for virtually unlimited
number of policy permutations down to the sub-application level.
The following configuration will use a Blanket-Suspect list style
deployment: