Before you begin to configure NSX with Policy Enforcer, configure the infected hosts workflow in VMWare vCenter Server.
To block the infected hosts:
Under the Manage section, click Security Tags column head and create SDSN_BLOCK security tag for NSX, as shown in Figure 110.
Figure 110: SDSN_BLOCK Security Tag
The feed for the infected hosts will be triggered by Sky ATP down to Policy Enforcer. When there is a trigger, the SDSN_BLOCK tag is attached to the VM. Click on the VM Count column to see the VM details attached to the tag.
The Service Composer page appears. From the Service Composer, click the Security Groups tab. The security administrator can create the security group based on the security tag.
In the Criteria Details row, select Security Tag from the list and provide the SDSN_BLOCK tag name, as shown in Figure 111.
Figure 111: Define Dynamic Membership Page
Click Next.
In the Service Composer page, under the Security Groups tab, you can see that the security group has been created and the VM with the security tag is assigned to the security group.
© 2017 Juniper Networks, Inc. All rights reserved