Setup Access Engine Policies
2 min
access engine helps with simple segment based l3 policy, such as intra segment or inter segment allow/deny rules, with optional external forwarding for sse first, make sure micro segmentation is enabled for the tenant or site once enabled, policy rules are received from cloud, and enforcement starts after the first rule is pushed to the dataplane open global settings → access engine and review the defaults the default internal behavior is any to any = deny, and the default external behavior is any to internet = forward to upstream firewall/router figure 1 below shows the default access engine rule view with one internal rule and one external rule already present figure 1 access engine rules page showing the default internal deny policy and default external forward to firewall policy to create an internal l3 policy, go to create rule → create internal rule start by selecting the source segment, then choose the destination segment, and finally set the action to allow or deny based on the required intra segment or inter segment behavior legacy access engine 1 0 rules are segment based figure 2 below shows the internal rule workflow starting with segment selection figure 2 internal rule creation flow where you begin by selecting the source segment if the customer needs sse forwarding, go to create rule → create external rule select the source segment, set the destination to all internet bound traffic, choose forward as the action, optionally select the configured sase provider, add rule name and description, and save figure 3 below shows the external rule example for forwarding internet bound traffic figure 3 external rule creation flow for forwarding a segment’s internet bound traffic to an sse provider after saving, confirm the rule appears in the access engine table and use rule log to validate behavior during testing
