Moving Prefilter Rules to an Access Control Policy

You can move prefilter rules from a prefilter policy to the associated access control policy.

Before you begin

Note the following conditions before you proceed:

  • Only prefilter rules can be moved to an access control policy. Tunnel rules cannot be moved.

  • The prefilter rules can be moved only to the associated access control policy.

  • The prefilter rules with configured interface groups cannot be moved.

  • The Action parameter in the prefilter rule is changed to a suitable action in the access control rule when moved. To know what each action in the prefilter rule maps to, see the following table:

    Action in the prefilter rule

    Action in the access control rule

    Analyze

    Allow

    Block

    Block

    Fastpath

    Trust

  • Similarly, based on the action configured in the prefilter rule, the logging configuration is set to an appropriate setting after the rule is moved, as mentioned in the following table.

    Action in the prefilter rule

    Enabled Logging configurations in the access control rule

    Analyze

    None of the log settings are enabled.

    Block

    • Log at Beginning of Connection

    • Event Viewer

    • Syslog Server

    • SNMP Trap

    Fastpath

    • Log at Beginning of Connection

    • Log at End of Connection

    • Event Viewer

    • Syslog Server

    • SNMP Trap

  • The comments in the prefilter rule configuration are lost after moving the rule. However, a new comment is added in the moved rule mentioning the source prefilter policy.

  • While moving rules from the source policy, if another user modifies those rules, the management center displays a message. You may continue with the process after refreshing the page.

Procedure


Step 1

In the prefilter policy editor, select the rules that you want to move with a left-click on your mouse.

Tip

To select multiple rules, use the Ctrl (Control) key on your keyboard.

Step 2

Right-click the selected rules and choose Move to another policy.

Step 3

Select the destination access control policy from the Access Policy drop-down list.

Step 4

From the Place Rules drop-down list, choose where you want to position the moved rules:

  • To position as the last set of rules in the Default section, choose At the bottom (within the Default section).
  • To position as the first set of rules in the Mandatory section, choose At the top (within the Mandatory section).

Step 5

Click Move.


What to do next

  • Deploy configuration changes.