Configure network analysis rules

Network analysis rules allow you to specify which network analysis policy should preprocess traffic that matches specific conditions, providing granular control over traffic inspection before intrusion detection.

Network analysis rules are configured within the advanced settings of an access control policy. You can create custom rules to apply different network analysis policies based on traffic conditions such as source, destination, ports, or applications.

Before you begin

Follow these steps to configure network analysis rules:

Procedure


Step 1

In the access control policy editor, click Advanced, then click Edit (edit icon) next to the Network Analysis and Intrusion Policies section.

If View (View button) appears instead, settings are inherited from an ancestor policy, or you do not have permission to modify the settings.If the configuration is unlocked, uncheck Inherit from base policy to enable editing.

Tip

Click Network Analysis Policy List to view and edit existing custom network analysis policies.

Step 2

Next to Network Analysis Rules, click the statement that indicates how many custom rules you have.

Step 3

Click Add Rule.

Step 4

Configure the rule's conditions by clicking the conditions you want to add.

Step 5

Click Network Analysis and choose the Network Analysis Policy you want to use to preprocess the traffic matching this rule.

Click Edit (edit icon) to edit a custom policy in a new window. You cannot edit system-provided policies.

Step 6

Click Add.


What to do next

  • Deploy configuration changes.