Skip to main content

About the Default Policy

Abstract

The CloudConnexa Default Policy is the catch-all Shield Policy that automatically applies to any User Group not assigned to a custom policy and always applies to Networks and Hosts—it can't be renamed or deleted, but you can set it to Inactive.

Overview

The Default Policy is the catch-all policy for Cyber Shield. It automatically applies to User Groups that aren't assigned to a custom Shield Policy and always applies to Networks and Hosts.

Every WPC has one Default Policy. Unlike a custom Shield Policy, the Default Policy:

  • Can't be renamed.

  • Can't be deleted.

  • Doesn't provide an Assign user groups control.

  • Automatically covers User Groups that aren't assigned to a custom policy.

  • Always applies to Networks and Hosts.

For an overview of the policy model, refer to About Shield Policies.

How the Default Policy applies to User Groups

You don't explicitly assign User Groups to the Default Policy. Instead, CloudConnexa automatically applies the Default Policy to any User Group that isn't assigned to a custom Shield Policy.

For example:

  • A newly created User Group uses the Default Policy until you assign it to a custom policy.

  • Removing a User Group from a custom policy returns it to the Default Policy.

  • Reassigning a User Group from one custom policy to another moves it directly to the new policy.

For information about assigning and reassigning User Groups, refer to Assign User Groups to a Shield Policy.

Networks and Hosts

Important

Networks and Hosts always use the Default Policy. You can't assign a custom Shield Policy to a Network or Host.

Changing the Default Policy's filtering settings therefore affects the Cyber Shield protection applied to Networks and Hosts, as well as User Groups that use the Default Policy.

Default Policy restrictions

The Default Policy is a system policy and behaves differently from custom Shield Policies.

In the Shield Policies list, the Default Policy displays a System badge. You can't:

  • Change its name.

  • Delete it.

  • Explicitly assign User Groups to it.

When you edit the Default Policy, its name is locked, and Delete Policy is disabled.

For more information about these controls, refer to Browse and Manage Shield Policies, Create or Edit a Shield Policy, and Delete a Shield Policy.

Active and Inactive Default Policy

Like any Shield Policy, the Default Policy can be Active or Inactive. There is no separate control for changing the policy's state.

  • Active: Domain Filtering, Traffic Filtering, or both are enabled.

  • Inactive: Both Domain Filtering and Traffic Filtering are disabled.

An Inactive Default Policy retains its configuration but doesn't apply Domain Filtering or Traffic Filtering.

For details about the available filtering settings, refer to Domain Filtering and Traffic Filtering.

Important

Networks and Hosts always use the Default Policy, even when it's Inactive. If the Default Policy is Inactive, Networks and Hosts receive no Domain Filtering or Traffic Filtering.