Configuring a policy to allow users access to allowed network resources
To configure a policy:
- Go to Policy & Objects > Firewall Policy and select Create New.
- Enter a name for the policy.
- In Incoming Interface, select SSL-VPN tunnel interface (ssl.root).
- In Outgoing Interface, select a destination interface.
- In Source:
- Select + to open the Selected Entries window.
- In User, search and select the SAML user group created in Creating a SAML group and the SSL VPN pool range object.
- Select Close.
- In Destination:
- Select + to open the Selected Entries window.
- In Address, search and select the destination address.
- Select Close.
- In the Schedule dropdown, select always.
- In Service:
- Select + to open the Selected Entries window.
- Search and select ALL.
- Select Close.
- Optionally, in the Security Profiles pane, select the required options.
- Click OK.
If more policies are required, modify the above steps as needed.