sk182252 - Dynamic Layer in Access Control Policy

Dynamic Layer in Access Control Policy

Product Multi-Domain Security Management, Security Gateways, Security Management
Version R82, R82.10
OS Gaia
Last Modified 2026-06-14

Solution

Table of Contents:

Introduction

Starting from R82, it is possible to configure Access Control rules directly on the Security Gateway with the Gaia API call set-dynamic-content. This saves time and helps automate various tasks.

On the Management Server, you configure a new Policy Layer (and configure it as a Dynamic Layer). On the Security Gateway, this Dynamic Layer works as a container for all Access Control rules you configure with the Gaia API call set-dynamic-content.

Requirements

  1. Management Server R82 and higher:

    • Security Management Server
    • Multi-Domain Security Management Server
  2. Security Gateway R82 and higher:

    • Security Gateway
    • ElasticXL Cluster
    • ClusterXL
    • Security Group on Maestro or Scalable Chassis
  3. On the Security Gateway, the user that runs the Gaia API must have this configuration in Gaia OS:

    1. Role: adminRole.
    2. Access Mechanism: Gaia API.
    3. Shell: /etc/cli.sh or /bin/bash

See the Gaia Administration Guide > chapter "User Management" > sections "Users" and "Roles".

Configuration

See the Security Management Administration Guide > Chapter " Creating an Access Control Policy" > section " Self-Managed Security Gateways".

Known Limitations

To remove dynamic rules, you must reset the Dynamic Layer that contains these rules on the Security Gateway.

Important Notes

Documentation

Article Properties

Access Level General
Status Approved
Date Created 2024-04-25
Last Modified 2026-06-14