04-Policies

HomeSupportSecurityH3C SecPath F5000 FirewallConfigure & DeployConfiguration GuidesH3C Firewall Products Comware 7 Web Configuration Guide(E1196 E8371)-6W70004-Policies
24-Zero trust policy
Title Size Download
24-Zero trust policy 24.24 KB

 

This help contains the following topics:

·     Introduction

·     Configure zero trust policy settings

Introduction

The zero trust policy defines the permissions for users to access assets based on the user and asset security status. The device uses the specified risk engine to evaluate security status of users and assets, and implements policy-based access control on access requests according to the evaluation information.

Configure zero trust policy settings

1.     Click the Policies tab.

2.     In the navigation pane, select Zero Trust > Zero Trust Policy.

3.     Configure zero trust policy settings.

Table 1 Zero trust policy configuration items

Item

Description

Risk engine URL

Enter the risk engine URL.

The device can use the risk engine to evaluate security status of users and assets.

The risk engine URL is a case-insensitive string in the format of protocol type://server IP address:port number/resource path, where:

·     The protocol type is HTTP or HTTPS. The default is HTTP.

·     The server IP address can only be an IPv4 address.

Controller VRF

Specify the name of the VPN instance to which the risk engine belongs. The name is a case-sensitive string.

Enable zero trust policy

Select the option to enable the zero trust policy feature.

After you select this option, you can click View connectivity to test the connectivity between the device and the specified risk engine.

The device predefines 16 policies. You can edit actions for the policies, but you cannot create or delete policies.

If the zero trust policy feature is disabled, the device cannot collaborate with the risk engine to evaluate security status of users and assets.

 

4.     To view security status of users or assets obtained from the risk engine, click the Risky User Info or Risky Asset Info tabs.

 

  • Cloud & AI
  • InterConnect
  • Intelligent Computing
  • Security
  • SMB Products
  • Intelligent Terminal Products
  • Product Support Services
  • Technical Service Solutions
All Services
  • Resource Center
  • Policy
  • Online Help
All Support
  • Become a Partner
  • Partner Resources
  • Partner Business Management
All Partners
  • Profile
  • News & Events
  • Online Exhibition Center
  • Contact Us
All About Us
新华三官网