---
title: "Configuring Security Policies"
canonical: "https://docs.infoblox.com/space/BloxOneThreatDefense/35371559/Configuring%20Security%20Policies"
format: markdown
---
<span style="color: #000000">A security policy is a set of rules and actions that you define to balance access and constraints, so you can mitigate malicious attacks and provide security for your networks. </span>

> ⚠️ ### Note
> ⚠️ 
> ⚠️ To provide flexibility and support for the new policy types, Infoblox Threat Defense has updated the evaluation process for security policies. Previously, Infoblox Endpoint and DNS Forwarding Proxy had implicit precedence over external networks. After the update, the policies are evaluated in the order you define and observe on the *Security Policies* page of the Infoblox Portal. If you have existing security policies, the policy precedence is updated to match the behavior that was defined before the update.

<span style="color: #000000">Infoblox Threat Defense provides a default global policy that gives you a head start in protecting your networks. You can review the default global policy, and decide whether you want to add or remove some of the rules based on your business requirements.</span>

<span style="color: #000000">In addition to the default global policy, you can add new security policies from scratch or clone an existing policy to complement the default policy. When you create a new security policy, you must first define a network scope to which you add external networks, user groups, DNS forwarding pro</span>xies, DDI IPAM, a<span style="color: #000000">nd Endpoint groups. Infoblox Threat Defense applies the security policy to all the entities that you include in the network scope. After you define the network scope, you can add policy rules and specify actions and their precedence order. For more information, see </span><span style="color: #000000">*[Security Policy Precedence](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35439943)*</span><span style="color: #000000">.</span>

<span style="color: #000000">To quickly create a new security policy, you can clone an existing one and modify certain elements before you save the new configuration.</span>

The *Security Policies* page displays the following information for each security policy you have configured by default:

1. **PRECEDENCE ORDER**: Infoblox Threat Defense enforces security policies in an ascending precedence order in which the policy rule with the lowest precedence order has the highest priority in the evaluation process.
2. **NAME**: The policy name.
3. **DEFAULT ACTION**: The default action currently configured for the entities that are not included in the network scope.
4. **DESCRIPTION**: The policy description.

For additional information on precedence order, see *[Security Policy Precedence](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35439943)*.  

You can also c<span style="color: #000000">lick the expandable menu icon to choose the following columns for display:</span>

- **EXTERNAL NETWORKS**: The total number of external networks included in the network scope for this policy.
- **INFOBLOX  ENDPOINT GROUPS**: The total number of endpoint groups included in the network scope for this policy.
- **IPAM**: The number of IPAM objects associated with the security
- **IPAM HOSTS**: The number of IPAM Hosts associated with the security policy.
- **TAGS**: Any tags associated with the security policy.
- **METADATA**: Any metadata associated with the security policy.
- **USER GROUPS**: The total number of user groups included in the network scope for this policy.
- **LISTS**: The total number of custom lists configured for the security policy.
- **CATEGORY FILTERS**: The total number of category filters configured for the security policy.
- **APPLICATION FILTERS**: The total number of application filters configured for the security policy.
- **BYPASS CODES**: The number of bypass codes associated with a security policy.
- **GEOLOCATION**: The geolocation state for the policy. Geolocation can be enabled or disabled. <span style="color: #000000">For more information about geolocation support, see </span><span style="color: #000000">*[Geolocation Support on a Per-Policy Basis](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35469854)*</span><span style="color: #000000">.</span>
- **SAFE SEARCH**: This indicates whether safe search is enabled or disabled for the security policy. <span style="color: #000000">For more information about safe search enforcement, see </span>*[Safe Search Enforcement](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35469836)*<span style="color: #000000">.</span>
- **DNS FORWARDING PROXIES**: The total number of DNS forwarding proxies included in the network scope for this policy.
- <span style="color: #000000">**DOH PER POLICY**</span><span style="color: #000000">: DNS over HTTPs (DoH) is an encrypted protocol for DNS resolution. DoH per Policy can be enabled or disabled. Infoblox  Threat Defense can terminate DoH connections and associate custom DoH FQDNs with specific customer policies. This allows customers to securely redirect their DNS traffic to Infoblox Threat Defense without a client and integrate our solution with third-party solutions. For information on how to use an agentless client over DoH, see </span><span style="color: #000000">*[Implementing the Client over DoH](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/611944899)*</span><span style="color: #000000">.</span>
- <span style="color: #000000">**BLOCK DNS REBIND ATTACK (BLOCK DRA)**</span><span style="color: #000000">: In a DNS rebinding attack, the attacker first gains control of a malicious DNS server. For information, see </span><span style="color: #000000">*[Blocking DNS Rebind Attacks](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/610861335)*</span><span style="color: #000000">.</span>
- **Local On-Prem Resolution**: For information on how to use Local Internet DNS Breakout (local on-prem resolution) with Infoblox Threat Defense and Universal DNS, see <u>*[Using Local On-prem Resolution](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35469508)*</u>.

> ⚠️ ### Note
> ⚠️ 
> ⚠️ The warning message will appear in the Infoblox Portal within 24 hours. Infoblox executes the job every 24 hours. If user1 makes changes during the first hour of this cycle, they will need to wait 23 hours to see those modifications reflected. Conversely, if user2 makes changes in the 23rd hour of the job cycle, they will only have to wait one hour to view their updates.


<span style="color: #000000">You can also view more information about each security policy in the right panel. When you expand </span><span style="color: #000000">**Network Scope**</span><span style="color: #000000">, </span><span style="color: #000000">**Policy Rules**</span><span style="color: #000000">, and </span><span style="color: #000000">**Bypass Codes**</span><span style="color: #000000">, you can see the total number of each entities within the respective category. When you click the number next to each entity, the system takes you to the </span><span style="color: #000000">**Summary**</span><span style="color: #000000"> page of the security policy. On the </span><span style="color: #000000">**Summary**</span><span style="color: #000000"> page, you can find more information about the specific entity or navigate to other sections to view or modify certain information about the security policy.</span>

<span style="color: #000000">You can also perform the following in this tab:</span>

- <span style="color: #000000">Click </span><span style="color: #000000">**Create Security Policy**</span><span style="color: #000000"> to create a new security policy.</span>
- <span style="color: #000000">Click the expandable menu icon > </span><span style="color: #000000">**Edit**</span><span style="color: #000000"> to modify the respective security policy information. You can also choose the respective security policy and click the </span><span style="color: #000000">**Edit**</span><span style="color: #000000"> button to do so.</span>
- <span style="color: #000000">Click the expandable menu icon > </span><span style="color: #000000">**Edit Precedence**</span><span style="color: #000000"> to set the precedence order for the security policy. Click the checkbox icon to save the changes, or click the close icon to discard the changes. For more information, see </span><span style="color: #000000">*[Security Policy Precedence](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35439943)*</span><span style="color: #000000">.</span>
- <span style="color: #000000">Choose a security policy and click </span><span style="color: #000000">**Clone**</span><span style="color: #000000"> to create a new policy by cloning the selected one.  </span>

- <span style="color: #000000">Click the expandable menu icon > </span><span style="color: #000000">**Remove**</span><span style="color: #000000"> to delete a security policy. You can also choose the respective security policy and click </span><span style="color: #000000">**Remove**</span><span style="color: #000000">.</span>
- <span style="color: #000000">Choose a security policy to view additional details in the right panel. You can collapse the right panel by clicking the information icon. </span>
- <span style="color: #000000">Enter the value that you want to search in the </span><span style="color: #000000">**Search**</span><span style="color: #000000"> text box. The Infoblox Portal displays the list of records that match the keyword in the text box.</span>
- <span style="color: #000000">Click the expandable menu icon to choose the columns you want to display or use the arrow keys to reorder the columns.</span>

<span style="color: #000000">For more information about how to create security policies, see the following:</span>

> Macro (children)