FireCloud Access Rules

Applies To: FireCloud Internet Access, FireCloud Total Access

FireCloud access rules determine when FireCloud allows or denies connections, what security services are applied to user traffic, and what private resources users can connect to. FireCloud applies a rule to each connection based on the user groups that the connecting user belongs to.

You can configure which of these security services apply to the traffic each rule handles:

  • Content Filtering — Blocks specific content categories and applications. For more information, go to Content Filtering in FireCloud.
  • Geolocation — Detects the geographic locations of connections to and from your network. You can enable and configure Geolocation to block access to and from specific locations. For more information, go to Add Geolocation Actions in FireCloud.
  • Content Scanning — Protects against spyware, viruses, malicious applications, spam email, and data leakage. For more information, go to Content Scanning in FireCloud.
  • Tunnel Bypass — Specifies IP addresses and networks whose traffic does not go through the FireCloud tunnel. For more information, go to Tunnel Bypass in FireCloud.

FireCloud has a Default rule that applies to all connections from all users. The Default rule has all security services enabled with default configuration settings. You cannot edit or delete the Default rule.

If you do not want to use the Default rule, you can disable it. If the Default rule is disabled and no other access rule applies to a user connection, FireCloud denies the connection.

You do not have to deploy your changes when you add, edit, or reorganize access rules.

When you edit an access rule and add a private resource, FireCloud refreshes the session for any users that the access rule applies to so that the users have access to the new resource.

Rule Priority

The rules list shows access rules in order of priority, from highest to lowest. For each connection, FireCloud applies the highest-priority rule that matches the source (the group that the user belongs to).

We recommend that you add each group to only a single access rule. If a group belongs to multiple access rules with different parameters, FireCloud applies only the access rule with the highest priority. This can prevent access to private resources if the access rule with the private resources has a low priority.

When you add a new rule, it shows in the highest position in the list. To change the order of access rules in the list, you can drag a rule to move it.

You cannot change the priority of the FireCloud Default rule. The Default rule has a lower priority than all other access rules, and is only used if it is the only rule or if no other rules apply.

Add FireCloud Rules

To create new rules for traffic that comes from specific user groups, you can add FireCloud access rules. When you add a rule, all available security services are enabled in the rule by default. In the rule settings for Content Filtering and Geolocation, you select which action the rule uses.

After you add a new rule, we recommend that you review the order of your access rules. FireCloud always adds a new rule in the highest position in the rule list, which makes it the highest priority rule.

To add a FireCloud rule, from WatchGuard Cloud:

  1. Select Configure > FireCloud.
  2. Click the Access Rules widget.
    The Access Rules page opens.
  3. Click Add Access Rule.
    The Add Rule page opens.
  4. In the Name text box, type a name for this rule.
  5. Specify the user groups the rule applies to. You can specify multiple groups for one rule.
    • If you use WatchGuard Cloud Directories and Domain Services for your identity provider, click Add User Group. Select the user groups that you want the rule to apply to, then click Add.
    • If you use a SAML identity provider, type the group names and press Enter or Return between each group name.
  6. If you do not want to allow users to disconnect from FireCloud, disable Allow Users to Manually Disconnect from FireCloud. This removes the Disconnect option from the Connection Manager on computers. This setting does not apply to mobile devices. Users can always choose to disconnect from FireCloud on mobile devices.

    When you disable this setting in an access rule, for the change to take effect in the Connection Manager, you must go to the Usage Report and manually log out impacted users that have already connected to FireCloud. This resets the cached Connection Manager authentication session.

  7. If you want FireCloud to include the X-Forwarded-For (XFF) header, enable Add XFF Header to Help Websites Display the Correct Language. The XFF header includes the public IP address of the user, and web browsers use this IP address for language localization. Some FireCloud users connect to a FireCloud point-of-presence with an egress IP address of a different country, which can cause browsers to show a different language than the user expects. This setting enhances the accuracy of language localization for users and improves the FireCloud experience.

  8. If you want to apply a custom maximum transmission unit (MTU) for the groups in this access rule, enable Apply a Specific MTU Value for This Access Rule, then select an MTU value.
  9. To enable or disable a security service, select the Internet Access tab, then click the toggle for the service. For Content Filtering and Geolocation, select the action for this rule to use from the drop-down list.
  10. To add a tunnel bypass to the access rule, from the Tunnel Bypass section, click Add Bypass. Select the tunnel bypass that you want the rule to apply to, then click Add.
  11. To configure Private Access settings, select the Private Access tab.
    1. To enable or disable security services that apply to connections to private resources, click the toggle for the service. For Content Filtering, you can select the action for this rule to use from the drop-down list.
    2. To give the user groups in this rule access to private resources, click Add Resource.
      The Add Resource page opens.
    3. Select the resources that you want to allow access to for the groups in this access rule. You can select private resources and Kerberos authentication resources as needed. Then click Add.
  12. Click Save.
    FireCloud creates the rule and adds it as the second-to-last rule in the list, above the Default rule.

Enable or Disable a FireCloud Rule

If you want to keep a rule but do not want the rule to apply to user traffic, you can disable the rule.

To enable or disable a rule:

  1. Select Configure > FireCloud.
  2. Click the Access Rules widget.
    The Access Rules page opens.
  3. In the Access Rules list, click the toggle in the Enabled column to enable or disable the access rule.

Related Topics

Content Scanning in FireCloud

Content Filtering in FireCloud

Add Geolocation Actions in FireCloud

Add Resources in FireCloud

Tunnel Bypass in FireCloud