Provides lookup details for segmentation rule categories, actions, catch-all behavior, and default rule behavior.
Segmentation rules define permissions between asset groups. Cyber Vision models and simulates rules in Release 5.6.0, but it does not deploy them to switches.
|
Rule category |
Purpose |
|---|---|
|
Inter-group rule |
Defines permissions between two different asset groups. |
|
Intra-group rule |
Defines permissions within the same asset group. |
|
Common service rule |
Defines reusable service access between one service group and many subscriber groups. |
|
Default rule |
Provides the global baseline when no explicit inter-group or common-service rule applies. |
Inter-group rules are unique by group pair. One pair has one shared action and one catch-all behavior, with separate directional protocol lists for each direction.
Segmentation rules table
From the main menu, choose Segmentation, and then select the Segmentation rules dashlet to manage global rules. Use the Inter-group rules, Intra-group rules, and Common service rules tabs to view each rule category.
Search for rules or filter them by asset group, action, protocol, or catch-all rule. Expand a rule to view the action and protocols configured for each traffic direction.
|
Field |
Description |
|---|---|
|
Asset group |
Identifies the asset groups to which the rule applies. Inter-group rules display two different groups. Intra-group rules display the same group on both sides. |
|
Action |
Shows whether the rule allows or denies traffic that matches a configured protocol. |
|
Protocol |
Lists the protocols configured for the rule. Expand the rule to review protocols by traffic direction. |
|
Catch all rule |
Shows the action applied to traffic that does not match a configured protocol. Cyber Vision sets this value to the opposite of the configured rule action. |
|
In use |
Shows the number of switches associated with the rule. Select the number to open the Segmentation rule in use summary and review the switches. |
Default rule behavior
The default rule is a single global baseline rule. Its default action is Allow, and you can edit the default action at any time.
When observed traffic hits the default rule and you create an override, Cyber Vision creates a new explicit group-pair rule instead of editing the default rule.
Select Show next to Default rule to display the group-pair rules derived from the default action. Select Hide default rules to display only explicit rules.
Use this table to interpret the configured action and protocol rows.
|
Configured action |
Specific protocols |
Any protocol |
|---|---|---|
|
Allow |
Allows the selected protocols and denies all other traffic between the groups. |
Allows the listed protocols and denies all other traffic between the groups. |
|
Deny |
Denies the selected protocols and allows all other traffic between the groups. |
Denies all traffic and locks the catch-all behavior. |