ATP100 - Security Policy in Nebula

Hi , I need a VLAN to block all internet traffic except Microsoft OneDrive on Android tablets and Windows apps

I've done a thousand tests with the Security policies, but it doesn't seem to work.

Has anyone personally tested this setup?
Do you have screenshots of the working configuration?
Thanks in advance

Fabrizio F.

All Replies

  • Zyxel_Jeff
    Zyxel_Jeff Posts: 1,059  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer

    Hi @FabrizioF

    Currently, we don’t support this scenario. The App Patrol profile can only support reject action, it doesn’t support only allow some specific apps that can be passed on a firewall rule.


  • mMontana
    mMontana Posts: 1,300  Guru Member
    First Anniversary 10 Comments Friend Collector First Answer
     The App Patrol profile can only support reject action, it doesn’t support only allow some specific apps that can be passed on a firewall rule.


    OUCH! What a giant feature hole!
  • Zyxel_Jeff
    Zyxel_Jeff Posts: 1,059  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer

    Thanks for your feedback and comment. We would consider transferring this request to our feature queue for our future development evaluation. Thanks.

  • in the end I "solved" by blocking everything as much as possible, Looking at the logs I then unblocked the sites required by the OneDrive app ... at the moment it seems to work, fingers crossed
  • Hi @FabrizioF

    Currently, we don’t support this scenario. The App Patrol profile can only support reject action, it doesn’t support only allow some specific apps that can be passed on a firewall rule.


    however I seem to have understood that in on-premises mode, it is possible to change this parameter instead ...
    it is a bug / limitation of Nebula mode
  • Zyxel_Jeff
    Zyxel_Jeff Posts: 1,059  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer
    FabrizioF said:

    Hi @FabrizioF

    Currently, we don’t support this scenario. The App Patrol profile can only support reject action, it doesn’t support only allow some specific apps that can be passed on a firewall rule.


    however I seem to have understood that in on-premises mode, it is possible to change this parameter instead ...
    it is a bug / limitation of Nebula mode
    Hi @FabrizioF  Thank you for your feedback. Currently, it's our design on the Nebula mode, we will put your feedback and comments for our future development evaluation. Thanks again!

Security Highlight