---
title: "Cloning Security Policies"
canonical: "https://docs.infoblox.com/space/BloxOneThreatDefense/35403967/Cloning%20Security%20Policies"
format: markdown
---
You can create a new security policy by cloning an existing one.

To clone a security policy:

1. <span style="color: #000000">From the Infoblox Portal, navigate to the Security Policies page (</span>**Security** > **Configuration** > **Security Policies**<span style="color: #000000">). </span>
2. <span style="color: #000000">On the </span><span style="color: #000000">*Security Policies*</span><span style="color: #000000"> page in the </span><span style="color: #000000">*Security Policies*</span><span style="color: #000000"> tab, select a policy you want to use as the baseline and click </span><span style="color: #000000">**Clone **</span><span style="color: #000000">at the top Action bar. The </span><span style="color: #000000">*Clone Security Policy*</span><span style="color: #000000"> wizard appears.</span>
3. <span style="color: #000000">On the </span><span style="color: #000000">*General*</span><span style="color: #000000"> page, complete the following:</span>
  - <span style="color: #000000">**Name**</span><span style="color: #000000">: Enter a name for the security policy. Ensure that you enter a unique name for each security policy. This is a required field.</span>
  - <span style="color: #000000">**Description**</span><span style="color: #000000">: Enter a brief description of the security policy. You can enter up to 256 characters. This is not a required field, but it is recommended. </span>
  - <span style="color: #000000">**Precedence**</span><span style="color: #000000">: Enter the precedence order for this policy, or use the arrows in the field to choose the precedence order for the policy. </span>
  - <span style="color: #000000">**Geolocation**</span><span style="color: #000000">: Toggle the Geolocation switch from </span><span style="color: #000000">**Disable**</span><span style="color: #000000"> to </span><span style="color: #000000">**Enable **</span><span style="color: #000000">(disabled by default) in order to enable the geolocation for the security policy, or accept the default disabled configuration for the security policy to preserve privacy. For more information about geolocation support, see </span><u><span style="color: #000000">*[Enabling and Disabling Geolocation for a Security Polic](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35469854)*</span></u><u><span style="color: #000000">[y](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35469854)</span></u><span style="color: #000000">.</span>
  - <span style="color: #000000">**Safe Search**</span><span style="color: #000000">: Toggle this switch from </span><span style="color: #000000">**Disable**</span><span style="color: #000000"> to </span><span style="color: #000000">**Enable**</span><span style="color: #000000"> (disabled by default). When safe search is enabled, inappropriate content from search results obtained from four major search engines (Google, Bing, YouTube, and Yandex) is filtered and restricted. Enabling safe search ensures that protected users will be unable to access or view inappropriate content. Enabling safe search does not override any configured custom lists or the default redirect. </span>
  - <span style="color: #000000">**DoH per Policy**</span><span style="color: #000000">: Switch the DoH per Policy toggle from </span><span style="color: #000000">**Disable**</span><span style="color: #000000"> to </span><span style="color: #000000">**Enable**</span><span style="color: #000000"> (disabled by default) to activate an encrypted protocol for DNS resolution. Once enabled, a textbox will display a custom, generated FQDN. You can click </span><span style="color: #000000">**Copy**</span><span style="color: #000000"> to accept the generated FQDN or click </span><span style="color: #000000">**Regenerate**</span><span style="color: #000000"> to generate a new FQDN. A pop-up window will then prompt you to confirm the refresh (regenerate) action for a new FQDN, indicating that the former FQDN will become invalid and this action cannot be undone. For information on how to use a client over DoH, see </span><span style="color: #000000">*[Implementing the Client over DoH](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/611944899)*</span><span style="color: #000000">.</span>
  - <span style="color: #000000">**Block DNS rebind attack**</span><span style="color: #000000">: Toggle this switch from </span><span style="color: #000000">**Disable**</span><span style="color: #000000"> to </span><span style="color: #000000">**Enable**</span><span style="color: #000000"> (disabled by default) to prohibits DNS rebinding attacks. For information, see </span><span style="color: #000000">*[Blocking DNS Rebind Attacks](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/610861335)*</span>
  - <span style="color: #000000">**Local on-Prem Resolution**</span><span style="color: #000000">: Toggle this switch from </span><span style="color: #000000">**Disable**</span><span style="color: #000000"> to </span><span style="color: #000000">**Enable**</span><span style="color: #000000"> (disabled by default) to enable Local on-Prem Resolution. For information, see </span><span style="color: #000000">*[Using Local On-Prem Resolution](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35469508)*</span><span style="color: #000000">*.*</span>
  - <span style="color: #000000">**Tags**</span><span style="color: #000000">: Tags can be added for DNS Forwarding Proxy, endpoints, endpoint groups, IPAM networks, individual IPs, IPAM Host objects, and ranges. Tags can also be added to Endpoint metatdata, OS and endpoint version. Policy rules can be defined by tags for custom lists, application filters and category filters. In the </span><span style="color: #000000">*Tags*</span><span style="color: #000000"> section, click </span><span style="color: #000000">**Add**</span><span style="color: #000000"> to add a tag. A tag consists of a </span><span style="color: #000000">**KEY**</span><span style="color: #000000"> (required) and a </span><span style="color: #000000">**Value**</span><span style="color: #000000">. When a security policy is created possessing a key and its corresponding value, all resource data having the same or similar key and the same or similar value will be associated with the security policy. For example, you can assign a security policy for firewalls. New firewalls will be automatically included in a policy when you add a relevant tag to an IPAM object. Or you can quarantine compromised or outdated endpoints (e.g. on Windows 8.1) by tags and metadata.  </span>
4. <span style="color: #000000">Click </span><span style="color: #000000">**Next**</span><span style="color: #000000">.</span>
5. <span style="color: #000000">On the </span><span style="color: #000000">*Network Scope*</span><span style="color: #000000"> page, define your network scope for this security policy. No network scope is inherited from the original security policy. For more information, see </span><span style="color: #000000">*[Configuring Network Scopes](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35373166)*</span><span style="color: #000000">.</span>
6. <span style="color: #000000">Click </span><span style="color: #000000">**Next**</span><span style="color: #000000">.</span>
7. <span style="color: #000000">On the </span><span style="color: #000000">*Policy Rules *</span><span style="color: #000000">page, all the policy rules are inherited from the original security policy. You cam make modifications to them. For more information, see </span><span style="color: #000000">*[Adding Policy Rules and Setting Precedence](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35403288)*</span><span style="color: #000000">.</span>
8. <span style="color: #000000">Click </span><span style="color: #000000">**Next**</span><span style="color: #000000">.</span>
9. <span style="color: #000000">On the </span><span style="color: #000000">*Bypass Codes*</span><span style="color: #000000"> page, all the bypass codes are inherited from the original security policy. You can make modifications to them. For more information, see </span><span style="color: #000000">*[Adding Bypass Codes to a Security Policy](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35373231)*</span><span style="color: #000000">.</span>
10. <span style="color: #000000">Click </span><span style="color: #000000">**Next.**</span>
11. <span style="color: #000000">On the </span><span style="color: #000000">*Summary*</span><span style="color: #000000"> page, review your configuration. This page displays the configuration details. You can click the </span>> Macro (inline-media-image)

<span style="color: #000000">icon next to a network scope or policy rule to view the details in the </span><span style="color: #000000">**Selected**</span><span style="color: #000000"> panel. Before saving the security policy, you can make modifications by clicking the respective pages on the left navigation panel. You can also click the </span><span style="color: #000000">**Back**</span><span style="color: #000000"> button to navigate back to previous steps in the w</span>izard.
12. Click **Save & Close **to** **save the configuration.

For additional information on security policies, see the following:

- <span style="color: #0000ff">*[Configuring Security Policies](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35439943)*</span>
- *[About Rule Actions](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35473746)*
- *[Security Policy Precedence](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35439943)*
- *[Geolocation Support on a Per-Policy Basis](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35469854)*