---
title: "Adding Policy Rules and Setting Precedence"
canonical: "https://docs.infoblox.com/space/BloxOneThreatDefense/35403288/Adding%20Policy%20Rules%20and%20Setting%20Precedence"
format: markdown
---
<span style="color: #000000">You can add custom lists, feeds and Threat Insight, and category filters to your policy rules. Depending on your business requirements, you can add as many feeds and Threat Insight, custom lists or category filters as you need and apply them to different security policies. Note that you must first define a custom list or a category filter before you can add it to the security policy. For information about how to create a custom list, see </span><span style="color: #000000">*[Creating Custom Lists](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35473695)*</span><span style="color: #000000">*.*</span><span style="color: #000000"> For information about how to add category or application filters, see </span><u><span style="color: #000000">*[Configuring Filters](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35469571)*</span></u><span style="color: #000000">. For information about tags, see </span><span style="color: #000000">*[Managing Tags](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/35397076)*</span><span style="color: #000000">*.*</span>

## <span style="color: #000000">Adding Policy Rules </span>

<span style="color: #000000">To add policy rules, apply actions, and set precedence, complete the following:</span>

1. <span style="color: #000000">On the </span><span style="color: #000000">*Policy Rules*</span><span style="color: #000000"> page of the </span><span style="color: #000000">*Create New Security Policy*</span><span style="color: #000000"> wizard, define the </span><span style="color: #000000">**Default Action**</span><span style="color: #000000"> for all the destinations that you have not included in the security policy, as follows:</span>
  - <span style="color: #000000">**Allow**</span><span style="color: #000000">: Grants traffic access to a domain or IP address that hits a particular feed or security policy.</span>
  - <span style="color: #000000">**Default Redirect**</span><span style="color: #000000">: Routes traffic to the default Infoblox page or a custom message that you have configured for the </span><span style="color: #000000">**Redirect Page**</span><span style="color: #000000">.</span>
  - <span style="color: #000000">**Custom Redirect**</span><span style="color: #000000">: Redirects traffic to a configured custom redirect, if one has been configured by the organization. </span>
2. <span style="color: #000000">Click the </span><span style="color: #000000">**Add Rule**</span><span style="color: #000000"> menu and choose one of the following policy types.</span>

> ⚠️ **Note**
> ⚠️ 
> ⚠️ <span style="color: #000000">**Applying Rules**</span>
> ⚠️ 
> ⚠️ <span style="color: #000000">When you choose a policy type, the system adds it to the table. You can perform the following for each rule:</span>
> ⚠️ 
> ⚠️ - <span style="color: #000000">Click </span><span style="color: #000000">**Select List**</span><span style="color: #000000"> to view available rules for the respective policy type.</span>
> ⚠️ - <span style="color: #000000">Click the </span><span style="color: #000000">**Action**</span><span style="color: #000000"> menu to set the action for each policy rule. For more information about what each action means, see </span><span style="color: #000000">*[About Rule Actions](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35473746)*</span><span style="color: #000000">.</span>
> ⚠️ - <span style="color: #000000">Set the precedence order for a policy rule by clicking the up and down arrows at the end of each row to move the rule to its desired rank. The system applies policy rules based on the precedence order. Although you have the flexibility to set precedence for each rule, it is important that you understand the ramification of putting certain policy rules before others. For more information, see </span><span style="color: #000000">*[Precedence Rules for Security Policies](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/939458577)*</span><span style="color: #000000">.</span>
> ⚠️ - <span style="color: #000000">Choose a policy rule and click </span><span style="color: #000000">**Remove**</span><span style="color: #000000"> to remove it from the list.</span>

- <span style="color: #000000">**Custom List: **</span><span style="color: #000000">Select this rule to add a custom list to the policy. Complete the following to add a custom list to a security policy:</span>
  - <span style="color: #000000">**OBJECT**</span><span style="color: #000000">: From the </span><span style="color: #000000">**OBJECT**</span><span style="color: #000000"> menu, select a custom list from among the available custom lists options. You can view the </span><span style="color: #000000">**Threat Level and Threat Confidence **</span><span style="color: #000000">scores for any available custom lists</span><span style="color: #000000">**. **</span><span style="color: #000000">Custom lists can be either allow lists or block lists, depending on the actions that you assign.  Click </span><span style="color: #000000">**Select **</span><span style="color: #000000">to add the custom list to the policy. </span>
  - <span style="color: #000000">**ACTION**</span><span style="color: #000000">: From the </span><span style="color: #000000">**ACTION**</span><span style="color: #000000"> menu, select an action type for the custom list to be added to your security policy. Action types include the following:   </span>
    - <span style="color: #000000">**Allow - No Log**</span><span style="color: #000000">: Allows filtering of custom lists without logging of responses. Events will not be displayed in </span><span style="color: #000000">*Security Activity*</span><span style="color: #000000"> reports.</span>
    - <span style="color: #000000">**Allow - With Log**</span><span style="color: #000000">: Allows filtering of custom lists with logging of responses.</span>
    - <span style="color: #000000">**Block - No Redirect**</span><span style="color: #000000">: Blocks filtering of custom lists when no redirection is used.</span>
    - <span style="color: #000000">**Block - Default Redirect**</span><span style="color: #000000">: Blocks filtering of custom lists when the default redirect is used.</span>
    - <span style="color: #000000">**Block - Redirect**</span><span style="color: #000000">: Blocks filtering of custom lists when a custom redirect is used.</span>
    - <span style="color: #000000">**Block (No Log) - No Redirect**</span><span style="color: #000000">: Blocks filtering of custom lists when no redirect is used. Events will not be displayed in </span><span style="color: #000000">*Security Activity*</span><span style="color: #000000"> reports.</span>
    - <span style="color: #000000">**Block (No Log) - Default Redirect**</span><span style="color: #000000">: Blocks filtering of custom lists when using the default redirect. Events will not be displayed in </span><span style="color: #000000">*Security Activity*</span><span style="color: #000000"> reports.</span>
    - <span style="color: #000000">**Block (No Log) - Redirect**</span><span style="color: #000000">: Blocks filtering of custom lists when using a redirect. Events will not be displayed in </span><span style="color: #000000">*Security Activity*</span><span style="color: #000000"> reports.</span>

<span style="color: #000000">You can also add a new custom list by selecting </span><span style="color: #000000">**New Custom List**</span><span style="color: #000000"> from among the available custom list options. </span>  
<span style="color: #000000">For more information about custom lists, see </span><span style="color: #000000">*[Custom Lists](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35473695)*</span><span style="color: #000000">.</span>

- <span style="color: #000000">**Feeds and Threat Insight**</span><span style="color: #000000">: Select this rule to add a feed or Threat Insight to the policy. Your custom TIDE feeds (TIDE Bring Your Own Feed or TIDE BYOF) are listed under the list of available feed options. Complete the following to add a feed or Threat Insight to a security policy:  </span>
  - <span style="color: #000000">**OBJECT**</span><span style="color: #000000">: From the </span><span style="color: #000000">**OBJECT**</span><span style="color: #000000"> menu, select a feed or Threat insight from among the available feed and Threat insight options. You can view the </span><span style="color: #000000">**Threat Level and Threat Confidence **</span><span style="color: #000000">scores for any available items</span><span style="color: #000000">**. **</span><span style="color: #000000">Click </span><span style="color: #000000">**Select **</span><span style="color: #000000">to add the feed or Threat insight to the policy. </span>
  - <span style="color: #000000">**ACTION**</span><span style="color: #000000">: From the </span><span style="color: #000000">**ACTION**</span><span style="color: #000000"> menu, select an action type for the feed or Threat Insight to be added to your security policy. Action types include the following:     </span>
    - <span style="color: #000000">**Allow - No Log**</span><span style="color: #000000">: Allows filtering of feeds and threat insight without logging of responses. Events will not be displayed in </span><span style="color: #000000">*Security Activity*</span><span style="color: #000000"> reports.</span>
    - <span style="color: #000000">**Allow - With Log**</span><span style="color: #000000">: Allows filtering of feeds and threat insight with logging of responses.</span>
    - <span style="color: #000000">**Block - No Redirect**</span><span style="color: #000000">: Blocks filtering of feeds and threat insight when no redirection is used.</span>
    - <span style="color: #000000">**Block - Default Redirect**</span><span style="color: #000000">: Blocks filtering of feeds and threat insight when the default redirect is used.</span>
    - <span style="color: #000000">**Block - Redirect**</span><span style="color: #000000">: Blocks filtering of feeds and threat insight when a custom redirect is used.</span>
    - <span style="color: #000000">**Block (No Log) - No Redirect**</span><span style="color: #000000">: Blocks filtering of feeds and threat insight when no redirect is used. Events will not be displayed in </span><span style="color: #000000">*Security Activity*</span><span style="color: #000000"> reports.</span>
    - <span style="color: #000000">**Block (No Log) - Default Redirect**</span><span style="color: #000000">: Blocks filtering of feeds and threat insight when using the default redirect. Events will not be displayed in </span><span style="color: #000000">*Security Activity*</span><span style="color: #000000"> reports.</span>
    - <span style="color: #000000">**Block (No Log) - Redirect**</span><span style="color: #000000">: Blocks filtering of feeds and threat insight when using a redirect. Events will not be displayed in </span><span style="color: #000000">*Security Activity*</span><span style="color: #000000"> reports.</span>

<span style="color: #000000">For more information, see </span><span style="color: #000000">*[Viewing Active Threat Intelligence Feeds](https://docs.infoblox.com/space/BloxOneThreatDefense/35403598/Viewing+Active+Threat+Intelligence+Feeds)*</span><span style="color: #000000">. </span>

- <span style="color: #000000">**Category Filter**</span><span style="color: #000000">: Select this rule to add a category filter to the policy. Category filters are content categorization rules that allow you to detect and filter internet content and traffic that you want to allow or block. +: </span>
  - <span style="color: #000000">**OBJECT**</span><span style="color: #000000">: From the </span><span style="color: #000000">**OBJECT**</span><span style="color: #000000"> menu, select a category filter from among the available  options. </span><span style="color: #000000">** **</span><span style="color: #000000">Click </span><span style="color: #000000">**Select **</span><span style="color: #000000">to add the category filter to the policy. </span>
  - <span style="color: #000000">**ACTION**</span><span style="color: #000000">: From the </span><span style="color: #000000">**ACTION**</span><span style="color: #000000"> menu, select an action type for the category filter to be added to your security policy. Action types include the following:   </span>
    - <span style="color: #000000">**Allow - No Log**</span><span style="color: #000000">: Allows filtering of categories without logging of responses. Events will not be displayed in </span><span style="color: #000000">*Security Activity*</span><span style="color: #000000"> reports.</span>
    - <span style="color: #000000">**Block - No Redirect**</span><span style="color: #000000">: Blocks filtering of categories when no redirection is used.</span>
    - <span style="color: #000000">**Block - Default Redirect**</span><span style="color: #000000">: Blocks filtering of categories when the default redirect is used.</span>
    - <span style="color: #000000">**Block - Redirect**</span><span style="color: #000000">: Blocks filtering of categories when a custom redirect is used.</span>
    - <span style="color: #000000">**Block (No Log) - No Redirect**</span><span style="color: #000000">: Blocks filtering of categories when no redirect is used. Events will not be displayed in </span><span style="color: #000000">*Security Activity*</span><span style="color: #000000"> reports.</span>
    - <span style="color: #000000">**Block (No Log) - Default Redirect**</span><span style="color: #000000">: Blocks filtering of categories when using the default redirect. Events will not be displayed in </span><span style="color: #000000">*Security Activity*</span><span style="color: #000000"> reports.</span>
    - <span style="color: #000000">**Block (No Log) - Redirect**</span><span style="color: #000000">: Blocks filtering of categories when using a redirect. Events will not be displayed in </span><span style="color: #000000">*Security Activity*</span><span style="color: #000000"> reports.</span>

<span style="color: #000000">You can also add a new category filter by selecting </span><span style="color: #000000">**New Category Filter**</span><span style="color: #000000"> from among the available custom list options. To create a custom list,  </span>  
<span style="color: #000000">For more information, see </span><span style="color: #000000">*[Creating Category Filters](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/56656287)*</span><span style="color: #000000">.</span>

- <span style="color: #000000">**Application Filter**</span><span style="color: #000000">: Select this rule to add an application filter to the policy. Application filters are application categorization rules that allow you to detect and filter internet content and traffic that you want to allow or block. Complete the following to add an application filter to a security policy</span>
  - <span style="color: #000000">**OBJECT**</span><span style="color: #000000">: From the </span><span style="color: #000000">**OBJECT**</span><span style="color: #000000"> menu, select an application filter from among the available  options. Click </span><span style="color: #000000">**Select **</span><span style="color: #000000">to add the application filter to the policy. </span>
  - <span style="color: #000000">**ACTION**</span><span style="color: #000000">: From the </span><span style="color: #000000">**ACTION**</span><span style="color: #000000"> menu, select an action type for the application filter to be added to your security policy. Action types include the following:   </span>
    - <span style="color: #000000">**Allow - No Log**</span><span style="color: #000000">: Allows filtering of applications without logging of responses. Events will not be displayed in </span><span style="color: #000000">*Security Activity*</span><span style="color: #000000"> reports.</span>
    - <span style="color: #000000">**Allow - With Log**</span><span style="color: #000000">: Allows filtering of applications with logging of responses.</span>
    - <span style="color: #000000">**Allow - Local Resolution**</span><span style="color: #000000">: Allows filtering of applications when local on-prem resolution is used.</span>
    - <span style="color: #000000">**Block - No Redirect**</span><span style="color: #000000">: Blocks filtering of applications when no redirection is used.</span>
    - <span style="color: #000000">**Block - Default Redirect**</span><span style="color: #000000">: Blocks filtering of applications when the default redirect is used.</span>
    - <span style="color: #000000">**Block - Redirect**</span><span style="color: #000000">: Blocks filtering of applications when a custom redirect is used.</span>
    - <span style="color: #000000">**Block (No Log) - No Redirect**</span><span style="color: #000000">: Blocks filtering of applications when no redirect is used. Events will not be displayed in </span><span style="color: #000000">*Security Activity*</span><span style="color: #000000"> reports.</span>
    - <span style="color: #000000">**Block (No Log) - Default Redirect**</span><span style="color: #000000">: Blocks filtering of applications when using the default redirect. Events will not be displayed in </span><span style="color: #000000">*Security Activity*</span><span style="color: #000000"> reports.</span>
    - <span style="color: #000000">**Block (No Log) - Redirect**</span><span style="color: #000000">: Blocks filtering of applications when using a redirect. Events will not be displayed in </span><span style="color: #000000">*Security Activity*</span><span style="color: #000000"> reports.</span>

<span style="color: #000000">You can also add a custom application filter by selecting </span><span style="color: #000000">**New Filter**</span><span style="color: #000000"> from the </span><span style="color: #000000">**Choose Application Filter**</span><span style="color: #000000"> menu. To create your custom application filter, you must provide a name for the custom application list; a description is optional. </span>  
<span style="color: #000000">For more information, see </span><span style="color: #000000">*[Creating Application Filters](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/56656233)*</span><span style="color: #000000">.</span>

- <span style="color: #000000">**Tag**</span><span style="color: #000000">: Select this rule to add a tag to the policy. Tags allow you to assign rules to objects in a security policy that allow you to detect and filter internet content and traffic that you want to allow or block based on the tag For security policies, tags consists of a name, an action, and a scope. Complete the following to add a tag to a security policy: </span>
  - <span style="color: #000000">**OBJECT**</span><span style="color: #000000">: An object is composed of three parts: </span><span style="color: #000000">**KEY**</span><span style="color: #000000">, </span><span style="color: #000000">**VALUE**</span><span style="color: #000000">, and </span><span style="color: #000000">**SCOPE**</span><span style="color: #000000">. From the </span><span style="color: #000000">**OBJECT**</span><span style="color: #000000"> menu, select a </span><span style="color: #000000">**KEY**</span><span style="color: #000000">, </span><span style="color: #000000">**VALUE**</span><span style="color: #000000">, and </span><span style="color: #000000">**SCOPE**</span><span style="color: #000000"> for the tag. All three components of the tag object must be specified when it is created. </span>
  - <span style="color: #000000">**ACTION**</span><span style="color: #000000">: From the </span><span style="color: #000000">**ACTION**</span><span style="color: #000000"> menu, select an action type for the tag to be added to your security policy. Action types include the following:   </span>
    - <span style="color: #000000">**Allow - No Log**</span><span style="color: #000000">: Allows filtering of tags without logging of responses. Events will not be displayed in </span><span style="color: #000000">*Security Activity*</span><span style="color: #000000"> reports.</span>
    - <span style="color: #000000">**Allow - With Log**</span><span style="color: #000000">: Allows filtering of tags with logging of responses.</span>
    - <span style="color: #000000">**Block - No Redirect**</span><span style="color: #000000">: Blocks filtering of tags when no redirection is used.</span>
    - <span style="color: #000000">**Block - Default Redirect**</span><span style="color: #000000">: Blocks filtering of tags when the default redirect is used.</span>
    - <span style="color: #000000">**Block - Redirect**</span><span style="color: #000000">: Blocks filtering of tags when a custom redirect is used.</span>
    - <span style="color: #000000">**Block (No Log) - No Redirect**</span><span style="color: #000000">: Blocks filtering of tags when no redirect is used. Events will not be displayed in </span><span style="color: #000000">*Security Activity*</span><span style="color: #000000"> reports.</span>
    - <span style="color: #000000">**Block (No Log) - Default Redirect**</span><span style="color: #000000">: Blocks filtering of tags when using the default redirect. Events will not be displayed in </span><span style="color: #000000">*Security Activity*</span><span style="color: #000000"> reports.</span>
    - <span style="color: #000000">**Block (No Log) - Redirect**</span><span style="color: #000000">: Blocks filtering of tags when using a redirect. Events will not be displayed in </span><span style="color: #000000">*Security Activity*</span><span style="color: #000000"> reports.</span>

<span style="color: #000000">**Precedence order considerations when defining a policy-based on tags: **</span><span style="color: #000000">If the Default Global Policy has higher precedence than a custom policy having network scopes defined based on tags, then the Default Global Policy will continue to work because its precedence is higher than the custom policy. For a custom policy having network scope defined based on tags to work, it should have higher precedence than the Default Global Policy. </span>  
<span style="color: #000000">For information on applying tags to Infoblox Threat Defense objects, see </span><span style="color: #000000">*[Applying Tags](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/35367538)*</span><span style="color: #000000">.</span>

<span style="color: #000000">3. After you add policy rules, set actions, and precedence, you can proceed to add bypass codes.</span>

<span style="color: #000000">4. Click </span><span style="color: #000000">**Next**</span><span style="color: #000000"> in the wizard to add bypass codes. For more information, see </span><span style="color: #000000">*[Adding Bypass Codes to a Security Policy](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35373231)*</span><span style="color: #000000">.</span>

<span style="color: #111111">For information on precedence order, see </span>*[Precedence Rules for Security Policies](https://docs.infoblox.com/space/BloxOneThreatDefense/939458577)*<span style="color: #111111">. </span><span style="color: #000000">For information about other tasks in creating a new security policy, see the following:</span>

- <span style="color: #ff0000">*[Configuring Security Policies](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35371559)*</span>
- *[Configuring Network Scopes](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35373166)*
- <span style="color: #ff0000">*[Adding Bypass Codes to a Security Policy](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35373231)*</span>