---
title: "Creating Security Policies"
canonical: "https://docs.infoblox.com/space/BloxOneThreatDefense/35469750/Creating%20Security%20Policies"
format: markdown
---
<span style="color: #000000">A security policy is a set of rules and actions that you define to balance access and constraints so you can mitigate malicious attacks and provide security for your networks. </span>

<span style="color: #3e3f40">To create a security policy, complete the following:</span>

1. <span style="color: #3e3f40">From the Infoblox Portal, click </span>**Security** > **Configuration** > **Security Policies**.
2. <span style="color: #3e3f40">In the </span><span style="color: #3e3f40">*Security Policies*</span><span style="color: #3e3f40"> tab, click </span><span style="color: #3e3f40">**Create Security Policy **</span><span style="color: #3e3f40">at the top Action bar</span><span style="color: #000000">. The </span><span style="color: #000000">*Create New Security Policy*</span><span style="color: #000000"> wizard appears.</span>
3. <span style="color: #000000">On the </span><span style="color: #000000">*General*</span><span style="color: #000000"> page, complete the following:</span>
  - <span style="color: #000000">**Name**</span><span style="color: #000000">: Enter a name for the security policy. Ensure that you enter a unique name for each security policy. This is a required field.</span>
  - <span style="color: #000000">**Description**</span><span style="color: #000000">: Enter a brief description of the security policy. You can enter up to 256 characters. This is not a required field, but it is recommended. </span>
  - <span style="color: #000000">**Precedence**</span><span style="color: #000000">: Enter the precedence order for this policy, or use the arrows in the field to choose the precedence order for the policy. </span>
  - <span style="color: #000000">**Geolocation**</span><span style="color: #000000">: Toggle the Geolocation switch from </span><span style="color: #000000">**Disable**</span><span style="color: #000000"> to </span><span style="color: #000000">**Enable **</span><span style="color: #000000">(disabled by default) in order to enable the geolocation for the security policy, or accept the default disabled configuration for the security policy to preserve privacy. For more information about geolocation support, see </span><u><span style="color: #000000">*[Enabling and Disabling Geolocation for a Security Polic](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35469854)*</span></u><u><span style="color: #000000">[y](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35469854)</span></u><span style="color: #000000">.</span>
  - <span style="color: #000000">**Safe Search**</span><span style="color: #000000">: Toggle this switch from </span><span style="color: #000000">**Disable**</span><span style="color: #000000"> to </span><span style="color: #000000">**Enable**</span><span style="color: #000000"> (disabled by default). When safe search is enabled, inappropriate content from search results obtained from four major search engines (Google, Bing, YouTube, and Yandex) is filtered and restricted. Enabling safe search ensures that protected users will be unable to access or view inappropriate content. Enabling safe search does not override any configured custom lists or the default redirect. For more information about safe search enforcement, see </span><span style="color: #000000">*[Safe Search Enforcement](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35469836)*</span><span style="color: #000000">.</span>
  - <span style="color: #000000">**DoH per Policy**</span><span style="color: #000000">: Switch the DoH per Policy toggle from </span><span style="color: #000000">**Disable**</span><span style="color: #000000"> to </span><span style="color: #000000">**Enable**</span><span style="color: #000000"> (disabled by default) to activate an encrypted protocol for DNS resolution. Once enabled, a textbox will display a custom, generated FQDN. You can click </span><span style="color: #000000">**Copy**</span><span style="color: #000000"> to accept the generated FQDN or click </span><span style="color: #000000">**Regenerate**</span><span style="color: #000000"> to generate a new FQDN. A pop-up window will then prompt you to confirm the refresh (regenerate) action for a new FQDN, indicating that the former FQDN will become invalid and this action cannot be undone. Infoblox Threat Defense can terminate DoH connections and associate custom DoH FQDNs with specific customer policies. This allows customers to securely redirect their DNS traffic to Infoblox  Threat Defense without a client and integrate our solution with third-party solutions. For information on how to use an agentless client over DoH, see </span><span style="color: #000000">*[Implementing Clients over DoH](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/611944899)*</span><span style="color: #000000">.</span>
  - <span style="color: #000000">**Block DNS rebind attack**</span><span style="color: #000000">: Toggle this switch from </span><span style="color: #000000">**Disable**</span><span style="color: #000000"> to </span><span style="color: #000000">**Enable**</span><span style="color: #000000"> (disabled by default) to prohibits DNS rebinding attacks. For information, see </span><span style="color: #000000">*[Blocking DNS Rebind Attacks](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/610861335)*</span><span style="color: #000000">.</span>
  - <span style="color: #000000">**Local On-Prem Resolution**</span><span style="color: #000000">: Toggle this switch from </span><span style="color: #000000">**Disable**</span><span style="color: #000000"> to </span><span style="color: #000000">**Enable**</span><span style="color: #000000"> (disabled by default) to enable Local On-Prem Resolution. For information, see </span><span style="color: #000000">*[Using Local On-Prem Resolution](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35469508)*</span><span style="color: #000000">*.*</span>
  - <span style="color: #000000">**Tags**</span><span style="color: #000000">: Tags can be added for DNS Forwarding Proxy, endpoints, endpoint groups, IPAM networks, individual IPs, IPAM Host objects, and ranges. Tags can also be added to Endpoint metatdata, OS and endpoint version. Policy rules can be defined by tags for custom lists, application filters and category filters. In the </span><span style="color: #000000">*Tags*</span><span style="color: #000000"> section, click </span><span style="color: #000000">**Add**</span><span style="color: #000000"> to add a tag. A tag consists of a </span><span style="color: #000000">**KEY**</span><span style="color: #000000"> (required) and a </span><span style="color: #000000">**Value**</span><span style="color: #000000">. When a security policy is created possessing a key and its corresponding value, all resource data having the same or similar key and the same or similar value will be associated with the security policy. For example, you can assign a security policy for firewalls. New firewalls will be automatically included in a policy when you add a relevant tag to an IPAM object. Or you can quarantine compromised or outdated endpoints (e.g. on Windows 8.1) by tags and metadata.  </span>  
* *
4. <span style="color: #000000">Click </span><span style="color: #000000">**Next**</span><span style="color: #000000">.</span>
5. <span style="color: #000000">On the </span><span style="color: #000000">*Network Scope*</span><span style="color: #000000"> page, define your network scope for this security policy. For more information, see </span><span style="color: #000000">*[Configuring Network Scopes](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35373166)*</span><span style="color: #000000">.</span>
6. <span style="color: #000000">Click </span><span style="color: #000000">**Next**</span><span style="color: #000000">.</span>
7. <span style="color: #000000">On the </span><span style="color: #000000">*Policy Rules *</span><span style="color: #000000">page, add policy rules, and set their actions and precedence. For more information, see </span><span style="color: #000000">*[Adding Policy Rules and Setting Precedence](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35403288)*</span><span style="color: #000000">.</span>
8. <span style="color: #000000">Click </span><span style="color: #000000">**Next**</span><span style="color: #000000">.</span>
9. <span style="color: #000000">On the </span><span style="color: #000000">*Bypass Codes*</span><span style="color: #000000"> page, add bypass codes to your security policy. For more information, see </span><span style="color: #000000">*[Adding Bypass Codes to a Security Policy](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35373231)*</span><span style="color: #000000">.</span>
10. <span style="color: #000000">Click </span><span style="color: #000000">**Next.**</span>
11. <span style="color: #000000">On the </span><span style="color: #000000">*Summary*</span><span style="color: #000000"> page, review your configuration. This page displays the configuration details. You can click the right-pointing arrow icon next to a network scope or policy rule to view the details in the </span><span style="color: #000000">**Selected**</span><span style="color: #000000"> panel. Before saving the security policy, you can make modifications by clicking the respective pages on the left navigation panel. You can also click the </span><span style="color: #000000">**Back**</span><span style="color: #000000"> button to navigate back to previous steps in the </span><span style="color: #000000">*Create New Security Policy*</span><span style="color: #000000"> wizard.</span>
12. <span style="color: #000000">Click </span><span style="color: #000000">**Save & Close **</span><span style="color: #000000">to</span><span style="color: #000000">** **</span><span style="color: #000000">save the configuration.</span>

For additional information on security policies, see the following:

- <span style="color: #0000ff">*[Configuring Security Policies](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35439943)*</span>
- *[About Rule Actions](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35473746)*
- *[Security Policy Precedence](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35439943)*
- *[Geolocation Support on a Per-Policy Basis](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35469854)*