•
View device pending policy—Displays the policy being pushed to a device including
prerules and postrules from current and parent domains.
•
Validate policy—Validates policy rules.
•
View domain rules—When checked, any predefined or custom policy displays the
prerules and postrules above and below the policy rules. These rules are displayed in
a different color and not editable.
prerules and postrules can include rulegroups. The firewall rulebase for prerules and
postrules cannot contain VPN rules or VPN links.
When the regional server pushes a rulebase to a device that is not contained within the
regular policy, a warning message is displayed in the Job Manager window notifying the
user that a rulebase was pushed that is not contained within the regular policy.
Rule Application Sequence
Since prerules and postrules are defined at the Central Manager, global, and subdomain
levels, NSM imposes a rule application precedence. When all prerules and postrules are
defined, the application order of rules in a rulebase are applied in the following order
(from first to last):
•
Central Manager pre rules
•
Global domain pre rules
•
Subdomain prerules
•
Specific rulebase rules the device uses
•
Subdomain postrules
•
Global domain postrules
•
Central Manager postrules
ScreenOS Devices
ScreenOS devices require rules to have unique IDs. Rules pushed to devices are the
merged result of prerules and postrules based on pre/post policy and local policy from
the device. Enforcing uniqueness at the single policy level is not sufficient.
With the Central Manager prerules and postrules, NSM enforces the uniqueness of a
device rule’s preferred ID server-wide. Therefore, when an administrator adds a domain
level pre/post rule either from the regional server or from the Central Manager server
pushing prerules and postrules to the regional server, the regional server generates a
server-wide unique preferred ID for the new rule. There is a preset ID range for firewall
rulebases.
Validation of prerules and postrules
In Central Manager servers, prerules and postrules are validated the same way as rules
validated in NSM policy manager. Central Manager pushes prerules and postrules to the
regional server and fills mapping tables with polymorphic objects. (See “Polymorphic
Objects” on page 522 for more details.) Invalid prerules and postrules in the regional server
are removed when the policy is pushed to a device during the device update operation.
Copyright © 2010, Juniper Networks, Inc.
520
Network and Security Manager Administration Guide
Summary of Contents for NETWORK AND SECURITY MANAGER 2010.3
Page 6: ...Copyright 2010 Juniper Networks Inc vi...
Page 36: ...Copyright 2010 Juniper Networks Inc xxxvi Network and Security Manager Administration Guide...
Page 52: ...Copyright 2010 Juniper Networks Inc 2 Network and Security Manager Administration Guide...
Page 90: ...Copyright 2010 Juniper Networks Inc 40 Network and Security Manager Administration Guide...
Page 144: ...Copyright 2010 Juniper Networks Inc 94 Network and Security Manager Administration Guide...
Page 146: ...Copyright 2010 Juniper Networks Inc 96 Network and Security Manager Administration Guide...
Page 234: ...Copyright 2010 Juniper Networks Inc 184 Network and Security Manager Administration Guide...
Page 310: ...Copyright 2010 Juniper Networks Inc 260 Network and Security Manager Administration Guide...
Page 364: ...Copyright 2010 Juniper Networks Inc 314 Network and Security Manager Administration Guide...
Page 366: ...Copyright 2010 Juniper Networks Inc 316 Network and Security Manager Administration Guide...
Page 478: ...Copyright 2010 Juniper Networks Inc 428 Network and Security Manager Administration Guide...
Page 576: ...Copyright 2010 Juniper Networks Inc 526 Network and Security Manager Administration Guide...
Page 580: ...Copyright 2010 Juniper Networks Inc 530 Network and Security Manager Administration Guide...
Page 592: ...Copyright 2010 Juniper Networks Inc 542 Network and Security Manager Administration Guide...
Page 684: ...Copyright 2010 Juniper Networks Inc 634 Network and Security Manager Administration Guide...
Page 690: ...Copyright 2010 Juniper Networks Inc 640 Network and Security Manager Administration Guide...
Page 696: ...Copyright 2010 Juniper Networks Inc 646 Network and Security Manager Administration Guide...
Page 698: ...Copyright 2010 Juniper Networks Inc 648 Network and Security Manager Administration Guide...
Page 748: ...Copyright 2010 Juniper Networks Inc 698 Network and Security Manager Administration Guide...
Page 778: ...Copyright 2010 Juniper Networks Inc 728 Network and Security Manager Administration Guide...
Page 870: ...Copyright 2010 Juniper Networks Inc 820 Network and Security Manager Administration Guide...
Page 872: ...Copyright 2010 Juniper Networks Inc 822 Network and Security Manager Administration Guide...
Page 898: ...Copyright 2010 Juniper Networks Inc 848 Network and Security Manager Administration Guide...
Page 908: ...Copyright 2010 Juniper Networks Inc 858 Network and Security Manager Administration Guide...
Page 910: ...Copyright 2010 Juniper Networks Inc 860 Network and Security Manager Administration Guide...
Page 995: ...PART 6 Index Index on page 947 945 Copyright 2010 Juniper Networks Inc...
Page 996: ...Copyright 2010 Juniper Networks Inc 946 Network and Security Manager Administration Guide...