Configuring ZTNA rule sets to dynamically tag agent-based remote users
This example demonstrates how to configure zero trust network access (ZTNA) tag names and ZTNA tagging rule sets with the following posture checks:
- Endpoint is running Windows and has antivirus (AV) software installed and running
- Endpoint is running Windows and does not have AV software installed or running
To configure a ZTNA tagging rule set for compliant endpoints:
- Go to Configuration > ZTNA Tagging, and click Create.
- In the Name field, enter the desired rule set name. For example, SASE-Compliant.
- Toggle Enabled on or off to enable or disable the rule.
- (Optional) In the Comments field, enter any desired comments.
- Under When the following rules match, click Create.
- Configure the rule:
- For Operating System, select Windows.
- From the Rule Type dropdown list, select AntiVirus.
- From the AntiVirus dropdown list, select AntiVirus Software is installed and running.
- Click OK.
- In the Tag Name dropdown list, create a tag named SASE-Compliant.
- Click OK.
To configure a ZTNA tagging rule set for non-compliant endpoints:
- Go to Configuration > ZTNA Tagging, and click Create.
- In the Name field, enter the desired rule set name. For example, SASE-Non-Compliant.
- Toggle Enabled on or off to enable or disable the rule.
- (Optional) In the Comments field, enter any desired comments.
- Under When the following rules match, click Create.
- Configure the Severity Level rule:
- For Operating System, select Windows.
- From the Rule Type dropdown list, select AntiVirus.
- Select Negate.
- From the AntiVirus dropdown list, select AntiVirus Software is installed and running.
- Click OK.
- In the Tag Name dropdown list, create a tag named SASE-Compliant.
- Click OK.