Concept and mechanism
In Secure Firewall, different actions provide different guarantees. Trust permits a flow without the deep inspection expected from an Allow rule with an associated intrusion policy. Monitor can record a match while evaluation continues toward another action; an event is not automatic proof of blocking. Policy also follows an operational lifecycle: edit, save, deploy to the device, and verify results. Skipping this distinction creates reports where the editor shows configuration the target does not yet run. A passive sensor receives copies and can detect activity, but that point is not inline to directly drop original packets.
Guided application
In a fictional pilot, the team changes a partner exception to add inspection. Acceptance should confirm deployed state and rehearse authorized synthetic traffic and expected detection with rollback criteria. At layer two, DAI validates ingress ARP according to trust context and binding information. A static server may lack a DHCP binding; an appropriate ARP ACL first requires validation of the legitimate association. Indiscriminately marking every access port trusted resolves the symptom by removing checking from a wider surface. Retain ports, VLANs, associations, and rehearsal results in handover. The aim is to let RUN distinguish an application issue from a policy that works as configured but was designed around incorrect assumptions.
Saving Allow with IPS does not prove the rule is already active on the firewall.
Common pitfalls
Event as blocking; Trust as inspected Allow; saved configuration as applied; broad exception for one static case.
Related topics: Risk, identity, and AI security · Encryption, VPNs, and APIs · Secure management and VPN diagnosis
Confirm intent, deployment, and effect separately.
Reference: Access control rules · 350-701 SCOR v2.0, effective 2026-08-27; core component of CCNP Security