What To Do? actions

What To Do? determines the outcome of content rules. They are the action(s) to take when a web content or traffic meets the specified set of conditions, thus, the content rule is triggered. In other words, what action(s) to take when your content security policy is violated.

What To Do? consists of two types of actions: a principal action called Primary Action, followed by an additional action called What Else To Do?.

Primary Action

Each content rule operates with a principal What To Do? action called Primary Action. Primary Action defines how detected web traffic is handled.

For example, in a Detect virus content rule, this action might be to Block the communication or Continue to the next rule.

 

Primary Action is used in two areas in Secure Web Gateway:

  • Primary Action in each Content Rule defines a principal action when the content rule is triggered. For example, to block the communication.

  • Primary Action in each Web Policy Route defines a terminal default action, which applies when none of the attached content rules are triggered and acted on. For example, to allow the communication.

Ensure that you are aware of the differences between them.

What Else To Do? actions

In addition to the principal Primary Action, you can define What Else To Do? action for a content rule. For example, to send a notification to an administrator.

The following actions are available:

See also...