Zero Trust Gateway Policy Rule Settings
Constructors
Properties
Add custom headers to allowed requests, in the form of key-value pairs. Keys are header names, pointing to an array with its header value(s).
Set by parent MSP accounts to enable their children to bypass this rule.
Settings for the Audit SSH action.
Configure how browser isolation behaves.
Enable the custom block page.
The text describing why this block occurred, displayed on the custom block page (if enabled).
Set by children MSP accounts to bypass their parent's rules.
Configure how session check behaves.
Add your own custom resolvers to route queries that match the resolver policy. Cannot be used when 'resolvednsthroughcloudflare' or 'resolvedns*internally' are set. DNS queries will route to the address closest to their origin. Only valid when a rule's action is set to 'resolve'.
Configure how Gateway Proxy traffic egresses. You can enable this setting for rules with Egress actions and filters, or omit it to indicate local egress via WARP IPs.
Set to true, to ignore the category matches at CNAME domains in a response. If unchecked, the categories in this rule will be checked against all the CNAME domain categories in a response.
INSECURE - disable DNSSEC validation (for Allow actions).
Set to true to enable IPs in DNS resolver category blocks. By default categories only block based on domain names.
Set to true to include IPs in DNS resolver indicator feed blocks. By default indicator feeds only block based on domain names.
Send matching traffic to the supplied destination IP address and port.
Configure a notification to display on the user's device when this rule is matched.
Override matching DNS queries with a hostname.
Override matching DNS queries with an IP or set of IPs.
Configure DLP payload logging.
Settings that apply to quarantine rules
Configure to forward the query to the internal DNS service, passing the specified 'viewid' as input. Cannot be set when 'dnsresolvers' are specified or 'resolvednsthrough*cloudflare' is set. Only valid when a rule's action is set to 'resolve'.
Enable to send queries that match the policy to Cloudflare's default 1.1.1.1 DNS resolver. Cannot be set when 'dnsresolvers' are specified or 'resolvedns_internally' is set. Only valid when a rule's action is set to 'resolve'.
Configure behavior when an upstream cert is invalid or an SSL error occurs.