Issue
When Chamber Security Control is enabled (Detection or Prevention mode), and Access Policy Security Control is disabled, a Learned Rule modification may adversely affect the Effective Rules Table (ERT). This may result in unexpected behavior and inadvertently block some traffic subject to the specified Access Policies.
Learned Rule modification includes applying Learned Rules (LRT) to Application Chamber policies (CRT), or moving rules between Applied Learned Rules and Learned Rules Pending Review (Skipped).
Workaround
To restore the correct effective rules after a Learned Rule modification described above, perform any one of the following steps:
In Onboarding Flow Management, go to Access Policies page, open and save an existing policy. No need to make any changes.
In Advanced Management, go to Profile Provisioning page, open and save the existing app profile. No need to make any changes.
Other configuration changes that also trigger the policy recalculation:
Add or Remove server to/from given Application
Change Chamber Security Control Level for given Application
Change Access Policy Security Control Level for given Application
Comments
0 comments
Please sign in to leave a comment.