Position an access control rule

Position rules correctly within an access control policy to ensure the first match wins behavior produces the intended security outcomes.

You can move an existing rule within an access control policy, or insert new rules in a desired location. When you add or move a rule to a category, the system places it last in the category.

Before you begin

Review rule order guidelines in Best practices for access control rules.

Procedure


Step 1

Do one of these:

  • New rule—Insert a new rule by hovering over the line between the existing rules, and clicking Add Rule. The location is selected in the Insert box in the Add Rule dialog box; you can select a different rule to adjust the location. You can also select Add Rule Above or Add Rule Below from the right-click menu.

  • Existing rules when viewing the rule table—Click and drag the rule to the new position. This action is final, you are not prompted to confirm it.

  • Existing rules when viewing the rule table—Right-click a single rule and select Reposition Rule. To move multiple rules as a group, select their checkboxes, then select Reposition Rules from the Select Bulk Action menu. You are prompted for where you want the rule to go.

  • Existing rule when editing the rule—Click the Reposition Rule icon next to the rule name.

Step 2

When editing or repositioning the rule, choose where you want to move or insert the rule, then click Move, Confirm, or Reposition (depending on what you are doing).

  • Choose into Mandatory or into Default.
  • Choose a into Category, then choose the category.
  • Choose above rule or below rule, then select the rule.

Step 3

Save the rule if you are editing it.

Step 4

Click Save to save the policy.


What to do next

  • Deploy configuration changes.