Secure Access Service Edge (SASE) allows you to create custom trigger templates and configure baseline elements. You can select an existing trigger template when configuring dynamic policy trigger conditions to simplify the process.
Background information
The SASE dynamic decision-making feature detects and responds to security threats in real time. It allows you to configure dynamic policies to automatically adjust security measures and take action on devices that match policy conditions.
Configure trigger templates
-
Log on to the Secure Access Service Edge console.
-
In the left-side navigation pane, select .
-
On the Trigger Templates tab, click Create Template.
-
In the Create Template panel, configure the Trigger Templates based on the following table.
Parameter
Description
Template Name
Enter a name for the template. The name must be 2 to 32 characters long and can contain Chinese characters, letters, digits, hyphens (-), and underscores (_).
Trigger Settings
Configure one or more trigger conditions and specify the logical relationship between them. For more information about the parameters, see Trigger configuration parameters.
The panel also contains a Description field that supports up to 100 characters. In the trigger settings area, click + Add Condition to add conditions with an AND relationship within the same group. Click + Add Group to add condition groups with an OR relationship. For each rule, you can use multi-level drop-down lists to select a data category, a specific attribute, a comparison operator, and a target value.
-
Click OK.
The following operations are available:
-
Filter: Filter by Template Name.
-
Edit: Click Details in the Operation column to edit the trigger template information in the Details panel.
-
Delete: Click Delete in the Actions column to delete the trigger template.
Configure baseline elements
The system provides four built-in baseline elements for compliance checks in dynamic policies. You can configure these elements to simplify setting trigger conditions.
-
Log on to the Secure Access Service Edge console.
-
In the left-side navigation pane, select .
-
On the Baseline Element tab, click the drop-down list in the upper-left corner to configure baseline elements for different operating systems.
The available operating systems are Windows and macOS.
-
Click Configure in the Operation column. In the Configure panel, configure the baseline element based on the following table.
Parameter
Description
Applicable operating system
High-risk Port Enabled
Configure the port numbers that must be disabled.
Windows, macOS
High-risk Software Used
Select the high-risk software that must be blocked. In addition to the default software, you can add more software options. For more information about how to add software to the blacklist, see the software blacklist.
Windows, macOS
Antivirus Software Disabled
Select from the list of built-in antivirus software. You cannot add other antivirus software options.
Windows, macOS
Windows Automatic Updates Not Enabled
This default setting checks whether Windows automatic updates are enabled.
Windows