Policies
The Policies page provides a unified space for administrators to define and manage rules from a single page and apply them to more than one network or application at the same time. The task of firewall configuration, blocking application access and wireless network availability schedules are managed as policies. You can create a maximum of 32 policies for an Instant On site. If more than once policy is created and activated, the policy with the higher priority will be applied first on the site. If there are many rules about the same element, the rule with the highest priority is applied and the remaining policies are discarded, using the smallest common factor:
- A category for an application policy.
- A network for a network schedule policy.
Instant On supports policy creation using the following methods:
- AI-Assisted policy creation—Policies are created using prompts in an interactive, text-based format. The Edit option allows you to modify the policy generated by the AI. AI-assisted policy creation is available on all site topologies, including sites with or without a secure gateway. For more information, see AI-Assisted Policy Creation.
- Manual policy creation—Sites without a secure gateway supports only the manual policy creation. You need to manually define the required parameter to configure the policy. Manual policy creation is available on all site topologies. For more information, see Manual Policy Creation.
Policy Support by Site Topology
Policies can be created on any site, but the available actions, sources, and destinations depend on the devices present in the site:
- On sites with a secure Gateway, the full set of policy capabilities is available, including client policies, application-category policies, Internet or domain or network destinations, port forwarding, and network routing.
- On switch-only sites (switches but no secure gateway), you can create network firewall policies with the Allow, Block, and Restrict acions. The source can be a specific IP address or subnet, or a wired network; the destination is a specific IP address or subnet.
- On AP-only sites, wireless network-to-application-category policies and IP-to-IP rules (IP address or subnet based) are supported. For APs with wired and wireless capabilities (such as AP11D and AP22D), wired network-to-IP address or subnet policies are also supported. Other wired-network firewall policies are not available.
The following capabilities require a secure gateway and are not available on gateway-less sites:
- Destinations such as the Internet, Domains, or Networks.
- The Same Network destination type, which is supported only with Keemun.
- Client-to-network policies, port forwarding, and network routing.
Wireless access points generally do not support using a wired network as the policy source; however, this capability is available on APs that support wired networks, such as the AP11D and AP22D. The 1830 switch series does not support firewall policies.
Policy Deployment
In HPE Networking Instant On network, policies are dynamically applied based on the site’s topology, ensuring rules, configurations, and settings are optimized based on network infrastructure and operational requirement. Wherever possible, the system is designed to automatically enforce the policies on the Instant On edge devices—devices situated at the periphery of the network topology. This automated enforcement enhances efficiency and responsiveness by minimizing latency and reducing reliance on centralized Instant On devices.
The system intelligently balances policy enforcement between edge and centralized devices through techniques such as tiered enforcement, lightweight processing, and cloud-assisted solutions. This approach ensures that each site operates optimally within its unique environment while maintaining a balance between performance and resource utilization.
The HPE Networking Instant On network applies the configured rules for a site in the following order:
- Configured Policies—These are the custom rules defined by administrators within the Policies section. They are applied first, following the priority order specified in the policy list.
- Default rules—Applicable only to sites with a deployed secure gateway, a set of default rules is automatically enforced. These rules are not visible in the user interface and include the following rule:
- All LAN ports are granted access to the internet by default.
- Communications between LAN networks are blocked by default.
- All application categories are permitted on all networks by default.
- Network Access Controls—Within the Access Control section, administrators can configure network access restrictions for wired or wireless clients based on destination IP addresses. For detailed instructions, refer to the Configuring Networks documentation.
Viewing Policies
The Policies page displays the list of policies created for the site, in order of their highest to lowest priority. To view the details of a policy, follow these steps:
- Tap the Policies (
) tile on the Instant On mobile app home page. The list of policies created by the administrator are displayed here in order of their highest priority.
- Tap on any of the policies in the list to view its details. The Policy Details page is displayed.
Reordering Priority
The list of policies are displayed in order of their highest to lowest priority. To change the order of the priority, follow these steps:
- Tap the (
) tile on the Instant On mobile app home page. The list of policies created by the administrator are displayed here in order of their highest priority.
- Press the = icon next to the policy and drag it above or below the policy you want to position it.
- Click Done.
AI-Assisted Policy Creation
AI-Assisted policy creation simplifies the process of setting up policies by allowing you to generate them through natural language prompts. Instead of manually configuring each setting, you can describe your requirements in plain text, and the system will automatically generate a policy based on your input.
AI-assistance is limited to policy creation only. Other Instant On configurations or any information beyond the scope of policy creation is not supported by the AI-assistance.
Policies can be created using the AI assistant (Assistant) or manual policy creation on any site topology. The categories of policies the assistant can create depend on the devices present in the site. A site with a secured gateway supports the following categories of policies:
- Site Policy—Allow or block port forwarding.
- Client Policy—Control destinations that can be accessed by clients on the network.
- Network Policy—There are three types of network policies:
- Network Activation—Activate or deactivate the network during specific times.
- Network Firewall—Allow or block incoming and outgoing traffic to protect against unauthorized access and threats.
- Network Access—Control destinations that can be reached from the network.
- Application Policy—Allow or block specific applications from being used on the network.
On a Switch-only site, the assistant creates network firewall policies (Allow, Block, Restrict) between IP/subnet or wired-network sources and IP or subnet destinations.
Limitation of AI-Assistance
- Policies cannot be edited using the AI-assistance. To edit an existing policy, tap on the policy to view the Policy Details screen.
- Creation of new schedule is not supported, only exciting schedules can be applied during new policy creation.
- To ensure that domain policy rules are correctly implemented for site clients within an HPE Networking Instant On environment, the clients must use the Secure Gateway as their DNS server.
Creating a Policy Using AI-Assistance
The following procedure describes how to create an AI-assisted policy:
- Tap the Policies (
) tile on the Instant On mobile app home page.
The Policies screen is displayed.
- Tap the (
) icon.The Create Policies screen is displayed.
- In the State a Policy by Intention text box, enter the policy requirement as a prompt.
You can also select from predefined suggestions displayed above the State a Policy by Intention text box. Swipe left to view the full list of predefined suggestions.
- Tap the Submit icon.
The AI assistant analyzes the input and initiates a conversation to gather all necessary details.
- Interact with the AI-assistant to refine and complete the policy details.
- The AI assistant generates the policy based on the interaction.
- To review and edit the AI-generated policy tap on the suggested policy.
The Policy Details screen is displayed.
- In the Policy Details, you can do the following:
- Manual edits to the suggested policy.
- After editing the policy, tap Done to save the changes and return to the Create Policies screen.
- Tap the Cancel X icon to discard the changes done to the policy and return to the Create Policies screen.
- Review the policy details.
After reviewing the generated policy, tap the back arrow
icon to return to the Create Policies screen.
- Manual edits to the suggested policy.
- In the Create Policies screen, tap Start Over
icon to delete the current conversation and begin again. This is an optional setting. - In the Create Policies screen, tap Delete
icon next to the policy to delete the proposed policy. This is an optional setting. - Tap Accept to confirm.
- Tap Create Policies.
The newly created policy is added at the end of the policy table.
Manual Policy Creation
Instant On supports manual policy creation on all site topologies. The available categories and rule options depend on the devices present in the site.
Creating a Network Policy
Instant On allows you to assign a single schedule to many different wireless networks instead of configuring a schedule per wireless network.
The following procedure describes how to create a network schedule policy:
- Tap the (
) tile on the Instant On mobile app home page. The Policies screen is displayed.
- Tap the (
) icon. The Create Policy pop-up screen is displayed. - Select Assistant to open the page using AI Assistant.
- Select Advanced to open the page without AI Assistant.
- The Create Policy screen is displayed.
- Under Set Policy Type, tap on the Networks tile.
- Tap Continue.
- Under Set Rule and Condition, configure the following settings:
- Action—Select one of the following actions for the rule:
- Enable—Makes a wireless network available for users to connect when the provided schedule is enabled.
- Disable—Makes a wireless network unavailable when the provided schedule is disabled.
- Under Networks, select one of the following:
- All Wireless Networks—Policy applicable on all the wireless networks.
- Selected Wireless Networks—Select networks from the Select networks list to which the rule will be applied. At least one network must be selected.
- Tap the back arrow (
) to return to the Set Policy Type screen. This is an optional setting.
- Action—Select one of the following actions for the rule:
-
Tap Continue. The Set Policy Applicability screen is displayed.
- Under Set Policy Applicability, configure the following settings:
- Identification, enter a name for the policy.
- Set the Priority for the policy.
- Under Position, select either Lower or higher.
- Under Policy, select a policy from the drop-down list.
- Under Schedule, select one of the following options:
- Always Active—Select this option to make the wireless network always available for users to connect.
- Existing Schedules—Select this option to use the existing schedules.
- Tap the back arrow
icon, to return to the Set Rule and Condition screen. This is an optional setting.
- Any time during policy creation, tap Cancel creation to cancel the policy creation. This is an optional setting.
- Tap Create Policy.
Creating an Application Policy
It is possible to allow or deny access to application categories for some or all wireless networks. Additionally, the Network condition can be configured. If the Network condition is not provided, the policy will be applied on all wireless networks.
The following procedure describes how to create an application policy:
- Tap the (
) tile on the Instant On mobile app home page. The Policies screen is displayed.
- Tap the (
) icon. The Create Policy screen is displayed - Under Actions, tap on the Applications tile.
- Tap Continue.
- Under Set Rule and Conditions, configure the following settings:
- Rule—Select one of the following actions for the rule:
- Allow—Allows traffic matching the specified application categories and wireless networks pass.
- Block—Blocks traffic matching the specified application categories and wireless networks.
- Under Networks, select one of the following:
- All Wireless Networks—Policy applicable on all the wireless networks.
- Selected Wireless Networks—Select networks from the Select networks list to which the rule will be applied. At least one network must be selected.
- Under To Access or From Accessing > Applications Categories—Select the application categories from the Applications Categories list for which the action needs to be applied. Tap the back arrow
icon to save the application list. For the current list of application categories, see Applications List.
- Tap the back arrow (
) to return to the Set Policy Type screen. This is an optional setting.
- Rule—Select one of the following actions for the rule:
- Tap Continue.
Displays Set Policy Applicability screen.
- Under Set Policy Applicability, configure the following settings:
- Identification, enter a name for the policy.
- Set the Priority for the policy.
- Under Position, select either Higher or Lower.
- Under Policy, select a policy from the drop-down list.
- Tap the back arrow
icon, to return to the Set Rule and Condition screen. This is an optional setting.
- Any time during policy creation, tap Cancel creation to cancel the policy creation. This is an optional setting.
- Tap Create Policy.