Network analysis rules
A network analysis rule is a preprocessing configuration component that
-
tailors preprocessing configurations to network traffic within access control policy advanced settings,
-
matches packets in top-down order by ascending rule number, starting at 1, and
-
preprocesses traffic according to the first rule where all conditions match.
Network analysis rule conditions and matching
You can add zone, network, and VLAN tag conditions to a rule. If you do not configure a particular condition for a rule, the system does not match traffic based on that criterion. For example, a rule with a network condition but no zone condition evaluates traffic based on its source or destination IP address, regardless of its ingress or egress interface. Traffic that does not match any network analysis rules is preprocessed by the default network analysis policy.