Passive and Active Policy. Native enforcement mechanism. Asset onboarding and offboarding.
Enforcement
Passive and Active Policy
Typically, application owners first deploy a microsegmentation policy in passive mode. In passive mode, policies monitor connections to assets without enforcing traffic restrictions, highlighting violations for review by system owners. Legitimate violations may prompt blocking when switching to active mode, while others indicate a need for policy adjustments to permit traffic. After observing traffic in passive mode, resolving violations, and adjusting policies as needed, system owners transition the policy to active mode for enforcement across the asset group.
Enforcement
Native enforcement mechanism
12Port Horizon utilizes the native OS security system to monitor and enforce network traffic, ensuring minimal impact on network performance.
Enforcement
Asset onboarding and offboarding
When asset tagging changes, the system automatically re-evaluates network rules according to the policy's selection criteria. The dynamic nature of asset tagging enables near-real-time onboarding and offboarding of assets, facilitating reconfiguration of physical devices as needed.