Create a Zero Trust Application Policy
This tasks configures a Zero Trust Application Policy.
Before you begin
Ensure that you complete all the prerequisites listed in Prerequisites for Zero Trust Application Policy.
Procedure
Step 1 | Choose . | ||
Step 2 | Click Add Policy. | ||
Step 3 | In the General section, enter the policy name in the Name field. The description field is optional. | ||
Step 4 | Enter a domain name in the Domain Name field. Ensure that the domain name is added to the DNS. The domain name resolves to the threat defense gateway interface from where the application is accessed. The domain name is used to generate the ACS URL for all private applications in an Application Group. | ||
Step 5 | Choose an existing certificate from the Identity Certificate drop-down list. Click the Add () icon to configure a certificate enrollment object. For more information, see Adding Certificate Enrollment Objects. | ||
Step 6 | Choose a security zone from the Security Zones drop-down list. Click the Add () icon to add a new security zone. To add security zones, see Create Security Zone and Interface Group Objects. | ||
Step 7 | In the Global Port Pool section, a default port range is displayed. Modify, if required. Port values range from 1024 to 65535. A unique port from this pool is assigned to each private application.
| ||
Step 8 | (Optional) In the Security Controls section, you can add an Intrusion or Malware and File policy:
| ||
Step 9 | Click Save to save the policy. |
What to do next
-
Create an Application Group. See Create an Application Group.
-
Create an Application. See Create an Application.
-
Associate a Zero Trust Application Policy with a device. See Set Targeted Devices for Zero Trust Access Policy
-
Deploy configuration changes. See Deploy Configuration Changes in the Cisco Secure Firewall Management Center Administration Guide.