Applying a Policy
You can quickly configure and start server scans by using policy groups. Simply create a group, add policies to it, and apply this group to servers. The agents deployed on your servers will scan everything specified in the policies.
Precautions
- When you enable the enterprise edition, the default policy group of this edition (including weak password and website shell detection policies) takes effect for all your servers.
- When you enable the premium or WTP edition, the edition is bound to default_premium_policy_group.
To create your own policy group, you can copy the default policy group and add or remove policies in the copy.
Accessing the Policies Page
- Log in to the management console.
- In the upper left corner of the page, select a region, click
, and choose .
- In the navigation pane, choose Security Operations > Policies.
Creating a Policy Group
- In the row where default_premium_policy_group (default policy group of the premium edition) resides, click Copy in the Operation column, as shown in Figure 1.
Figure 1 Copying a policy group
- In the dialog box displayed, enter a policy group name and description, and click OK, as shown in Figure 2.Note
- The name of a policy group must be unique, or the group will fail to be created.
- The policy group name and its description can contain only letters, digits, underscores (_), hyphens (-), and spaces, and cannot start or end with a space.
Figure 2 Creating a policy group
- Click OK.
- Click the name of the policy group you just created. The policies in the group will be displayed, as shown in Figure 3.
Figure 3 Policies in a group
- Click a policy name and modify its settings as required. For details, see Modifying a Policy.
- Enable or disable the policy by clicking the corresponding button in the Operation column.
Applying a Policy Group
- In the navigation pane, choose Servers. Click the Server tab.
- Select one or more servers and click Apply Policy, as shown in Figure 4.
Figure 4 Applying policies
- In the dialog box that is displayed, select a policy group and click OK.
Figure 5 Selecting a policy group
Note- Old policies applied to a server will become invalid if you apply new policies to the server.
- Policies are applied to the servers within 1 minute.
- Policies applied to offline servers will not take effect until the servers are online.
- In a deployed policy group, you can enable, disable, or modify policies.
- A policy group that has been deployed cannot be deleted.
Parent topic: Server Management
- Precautions
- Accessing the Policies Page
- Creating a Policy Group
- Applying a Policy Group