The Security Policies screen enables you to define specific security behavior for one or more of your IoT device groups.
Basics

- Network Security Mode (Zero Trust enabled/disabled)
- Blocked traffic rules
- Allowed traffic rules
Note: Each IoT device group (service profile) can only have one security policy assignment, but you can assign a security policy to multiple IoT device groups.
Security Policy Example
An Enterprise company has several different connected IoT product lines. One is a smart refrigerator that incorporates an Internet browser function and requires access to the open Internet. Another product line is a connected personal health monitor that relays sensitive medical information (e.g., heart rate, Sp02, and blood pressure) to a receiving clinic. These two product lines have very different network security needs.
Product | Security Needs |
---|---|
Smart Refrigerator |
|
Medical Monitor |
|
The Security Policies feature enables you to create two different security policies, each tailored to the specific security needs of each product line. You can apply the “Smart Refrigerator” security policy to the service profile that contains the refrigerators, and the “Medical Monitor” security policy to the service profile that includes the monitors.
Creating a Policy
- Log in to the Aerport portal.
- Click Security > Security Policies in the left navigation menu.
- Click Create at the top right corner of the screen.
- In the popup window, populate the Name and Description
field.
- Click Create Now. The new policy appears on the Security Policies screen.
Defining a Policy
- Click Security > Security Policies in the left navigation menu.
- Locate the security policy you want to define.
- Click the pencil icon to define the policy.
- In the General Settings tab, review the populated fields and settings.
Note: Zero Trust Network is enabled by default. To learn more about the Zero Trust Network settings, see Zero Trust Network.
- Click Save Settings.
- Do one of the following:
- If the Zero Trust Network is Disabled, click the Blocked Traffic tab to block traffic.
- If the Zero Trust Network is Enabled, click the Allowed Traffic tab to allow traffic.
- Click +Traffic at the top right corner of the screen to block or allow
traffic.
- Select one of the following:
- Enter Traffic Details:
- Select a Traffic Direction:
- Mobile Originated (MO): Traffic coming from the device.
- Mobile Terminated (MT): Traffic going to the device.
- Populate the following fields:
- Endpoint IP Address or IP Range: IP Address or range of IP
addresses. Note: For examples on how to enter protocols, click the question mark.
- Protocol: Data transfer protocol.Note: For examples on how to enter protocols, click the question mark.
- Port Number(s) or Range(s): Number of the port.
- Description: Description of the traffic.
- Endpoint IP Address or IP Range: IP Address or range of IP
addresses.
- Click Save at the top right corner of the screen. A confirmation banner appears.
- Select a Traffic Direction:
- Select from observed traffic:
- (Optional) To filter the list, click View Last 7 Days to select the desired time frame from the drop-down menu and then click Update Results.
- Select the traffic endpoint(s) you want to block or allow.
- Click Save at the top right corner of the screen. A confirmation banner appears.
- Enter Traffic Details:
- (Optional) Once you add traffic endpoints, you can select one of the following
action icons:
- Play/Pause: Temporarily enables/disables endpoint traffic rule.
- Pencil: Edit the traffic rule details.
- Trash: Deletes the traffic rule.
Zero Trust Network
- All traffic is allowed, except for the endpoints listed in the Blocked Traffic tab.
- The rules listed in the Allowed Traffic tab are not in effect. You can edit this list without affecting network traffic.
- All traffic is blocked, except for the endpoints listed in the Allowed Traffic tab.
- The rules listed in the Blocked Traffic are not in effect. You can edit this without affecting network traffic.
Assigning a Policy
- Click Security > Security Policies in the left navigation menu.
- Click Assign at the top right corner of the screen. This opens the Policy
Assignment screen.
- Locate the service profile you want to assign.
- Click the pencil icon on the service policy. This opens the Edit Assignment
window.
- Select the security policy from the Choose Security Policy drop-down
menu.Note: To remove a policy from a service profile, select none from the drop-down menu.
- Click Save. Now you can see the security policy assigned to the service
profile.
0 Comments