Add Rules to a Policy

Procedure


Step 1

Select Policies > ASA Policies.

Step 2

Select the network policy you want to edit.

Step 3

Click Edit Policy.

Step 4

In the details pane, click in the Edit Tools toolbar to add a rule to the network policy. The new rule is added above the highlighted rule in the policy. Rules are prioritized by position in the list of rules from 1 to "last."

Note

New rules are assigned the Permit action by default.

Step 5

Click Save. Defense Orchestrator identifies which device is affected by the change.

Step 6

Review the Devices field in the policy details pane. If you have exceeded the optimal number of entries, you will get a warning like, "ACE count exceeded, 500 max entries, 1000 found" depending on the ASA hardware model the ASA is installed on.

Step 7

Review and deploy the changes you made now, or wait and deploy multiple changes at once.