Cisco Cyber Vision New UI Administration Guide, Release 5.6.0

PDF

Cisco Cyber Vision New UI Administration Guide, Release 5.6.0

Segmentation rules

Want to summarize with AI?

Log in

Provides lookup details for segmentation rule categories, actions, catch-all behavior, and default rule behavior.


Segmentation rules define permissions between asset groups. Cyber Vision models and simulates rules in Release 5.6.0, but it does not deploy them to switches.

Table 1. Rule categories

Rule category

Purpose

Inter-group rule

Defines permissions between two different asset groups.

Intra-group rule

Defines permissions within the same asset group.

Common service rule

Defines reusable service access between one service group and many subscriber groups.

Default rule

Provides the global baseline when no explicit inter-group or common-service rule applies.

Inter-group rules are unique by group pair. One pair has one shared action and one catch-all behavior, with separate directional protocol lists for each direction.

Segmentation rules table

From the main menu, choose Segmentation, and then select the Segmentation rules dashlet to manage global rules. Use the Inter-group rules, Intra-group rules, and Common service rules tabs to view each rule category.

Search for rules or filter them by asset group, action, protocol, or catch-all rule. Expand a rule to view the action and protocols configured for each traffic direction.

Table 2. Segmentation rule information

Field

Description

Asset group

Identifies the asset groups to which the rule applies. Inter-group rules display two different groups. Intra-group rules display the same group on both sides.

Action

Shows whether the rule allows or denies traffic that matches a configured protocol.

Protocol

Lists the protocols configured for the rule. Expand the rule to review protocols by traffic direction.

Catch all rule

Shows the action applied to traffic that does not match a configured protocol. Cyber Vision sets this value to the opposite of the configured rule action.

In use

Shows the number of switches associated with the rule. Select the number to open the Segmentation rule in use summary and review the switches.

Default rule behavior

The default rule is a single global baseline rule. Its default action is Allow, and you can edit the default action at any time.

When observed traffic hits the default rule and you create an override, Cyber Vision creates a new explicit group-pair rule instead of editing the default rule.

Select Show next to Default rule to display the group-pair rules derived from the default action. Select Hide default rules to display only explicit rules.

Use this table to interpret the configured action and protocol rows.

Table 3. Action and catch-all behavior

Configured action

Specific protocols

Any protocol

Allow

Allows the selected protocols and denies all other traffic between the groups.

Allows the listed protocols and denies all other traffic between the groups.

Deny

Denies the selected protocols and allows all other traffic between the groups.

Denies all traffic and locks the catch-all behavior.


Intra-group rules

An intra-group rule defines how Cyber Vision models traffic within one asset group. The traffic uses the same effective SGT on both sides of the relationship.

In Release 5.6.0, Cyber Vision initializes each intra-group rule as an explicit allow-any rule with deny catch-all behavior. This setup permits traffic inside the group because traffic matches the allow-any rule before it reaches the catch-all behavior.

Cyber Vision creates intra-group rules for relevant asset groups. You cannot create additional intra-group rules. You can review and edit an existing rule when you need to model traffic inside a group differently.

Cyber Vision Release 5.6.0 does not generate recommendations for intra-group rules.


Edit an intra-group rule

Edit an intra-group rule to allow or deny selected protocols between members of the same asset group.

Cyber Vision creates intra-group rules for relevant asset groups. You cannot create additional intra-group rules, but you can change the action and protocols of an existing rule.

Before you begin

Identify the asset group and the protocols that you want to allow or deny within the group.

Procedure

  1. From the main menu, choose Segmentation.

  2. Select the Segmentation rules dashlet.

  3. Select Intra-group rules.

  4. Open the actions menu for the asset group that you want to configure, and then select Edit.

  5. Select Allow or Deny in Action.

  6. Add or remove protocols for traffic within the asset group.

    Select a predefined protocol, or select Custom rules to define a protocol by port or port range.

  7. Review the catch-all behavior and generated command preview.

  8. Select Save.

Cyber Vision updates the intra-group rule. The rule retains the same asset group and uses the updated action and protocols in segmentation simulations.


Add an inter-group rule

Use an inter-group rule to define how Cyber Vision models traffic between two asset groups.

Before you begin

Identify the two asset groups, the expected traffic direction, and the protocols that should be allowed or denied.

If the required protocol is not available in the predefined list, identify the transport protocol, port or port range, and optional protocol tag for the custom rule.

Review existing rules first because an inter-group rule is unique for a group pair.

Procedure

  1. From the main menu, choose Segmentation.

  2. Select the Segmentation rules dashlet.

  3. Select Inter-group rules, and then select Add.

  4. Select the first asset group in Group A.

  5. Select the second asset group in Group B.

  6. Select Allow or Deny in Action.

  7. Review the Catch all rule that applies to traffic between the two groups that does not match a protocol row.

  8. Add protocols for the direction from Group A to Group B, the direction from Group B to Group A, or both directions.

    Select protocols from the predefined list, or select Custom rules to define a protocol by port or port range.

  9. To add a custom protocol, select Add custom rule, configure the protocol and port values, and then select Save.

    Add a protocol tag when you need a recognizable label for the custom protocol.

  10. Review the generated command preview.

    Use the inline or side-by-side view to verify how the selected action and directional protocols change the logical configuration.

  11. Select Save.

Cyber Vision adds the inter-group rule and displays it in the Inter-group rules table. The rule can be used in simulations for switches where both groups are relevant.


Edit an inter-group rule

Edit an inter-group rule when you need to change how Cyber Vision models traffic between two asset groups.

An inter-group rule retains its Group A and Group B association. You can change its action and the protocols configured for either traffic direction.

Before you begin

Identify the inter-group rule and the protocols that you want to allow or deny.

Procedure

  1. From the main menu, choose Segmentation.

  2. Select the Segmentation rules dashlet.

  3. Select Inter-group rules.

  4. Select the rule that you want to change, and then select Edit in the rule details.

  5. Select Allow or Deny in Action.

  6. Add or remove protocols for either traffic direction.

    Select a predefined protocol, or select Custom rules to define a protocol by port or port range.

  7. Review the catch-all behavior and generated command preview.

  8. Select Save.

Cyber Vision updates the inter-group rule and uses the updated action and protocols in segmentation simulations.


Edit the default segmentation rule

Edit the default rule to allow or deny traffic that does not match an explicit inter-group or common service rule.

The default rule is global. A change to its action affects the modeled behavior for all group pairs that rely on the default rule.

Before you begin

Review the explicit segmentation rules and determine whether unmatched traffic should be allowed or denied.

Procedure

  1. From the main menu, choose Segmentation.

  2. Select the Segmentation rules dashlet.

  3. On the Inter-group rules tab, locate Default rule, and then select Edit.

  4. Select Allow or Deny in Action.

  5. Select Save.

Cyber Vision updates the default action. Group-pair traffic that does not match an explicit rule uses the updated action in segmentation simulations.

What to do next

Select Show next to Default rule to review the group-pair rules derived from the updated default action.


Common service rules

Common service rules reduce repeated pair rules for shared services such as DNS, NTP, infrastructure services, and quarantine services. A common service rule connects one service group with many subscriber groups.

Common service groups

A common service group is not a special group type. It is an asset group that has common service rules associated with it.

Common service groups are global.

Local group subscriptions

Local groups cannot themselves be common service groups. A local group can explicitly subscribe to a global common service from the switch. Local groups do not automatically inherit parent or global common-service subscriptions.

After a group is configured as a common service, relationships involving that group are managed through common service rules. Regular inter-group rules are not allowed for common service groups. Converting an existing group into a common service can replace regular rules, which can affect multiple switches.


Add a common service rule

Use a common service rule when many groups need the same access to one shared service group, such as a DNS or NTP server group.

Caution

After an asset group is configured for common services, relationships to and from that group are managed through common service rules instead of regular inter-group rules.

Before you begin

Identify the service group, the groups that need access to that service group, and the protocols that should be allowed or denied.

Procedure

  1. From the main menu, choose Segmentation.

  2. Select the Segmentation rules dashlet.

  3. Select Common service rules, and then select Add.

  4. Select the asset group that provides the shared service in Select group.

  5. Select Allow or Deny in Action.

  6. Add protocols under Outbound traffic, Inbound traffic, or both.

    Use Outbound traffic for traffic that the service group initiates to included groups. Use Inbound traffic for traffic that included groups initiate to the service group.

  7. Review the Catch all rule.

    Groups that are included in the rule use this common service rule. Groups that are not included follow the system-wide default rule.

  8. Under Inclusions, select the groups that the common service rule applies to.

  9. Select Add.

Cyber Vision adds the common service rule for the selected service group and included groups.


Switch-specific rules

On the Segmentation page, select a switch from the list to view the segmentation rules relevant to that switch. The Segmentation rules tab displays the inter-group and intra-group rules associated with asset groups available on the selected switch.

Common service rules are global rules. Manage them from Global definitions > Segmentation rules > Common service rules.

Use this view to review the rules that apply to the selected switch and whether switch-local behavior differs from global intent. The switch-specific view limits the available asset groups and rules to those that are relevant to the selected switch.

You can add an inter-group rule from the switch-specific view. Cyber Vision limits the Group A and Group B selections to groups available for that switch.

In the global rules table, select a value in the In use column to identify the switches associated with a rule.