Default prefilter policy

A default prefilter policy only analyzes plain-text encapsulated tunnels. It is automatically assigned when you create a new access control policy. It cannot be deleted from the system.

Default prefilter policy characteristics

Every access control policy must have an assigned prefilter policy. For convenience, the system includes a default prefilter policy that is automatically assigned when you create a new access control policy.

You can instead change the default policy to block all plain-text tunnels. See Configuring the default action.

If you want to do any other customization, including adding prefilter or tunnel rules, you must create your own prefilter policy and assign it to the appropriate access control policies, as explained in Assign access control policy to devices.