<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco Secure Access Policy for Mobile Devices in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/cisco-secure-access-policy-for-mobile-devices/m-p/5303496#M8892</link>
    <description>&lt;P&gt;Make sure the security profile you’re assigning to that rule actually supports web content categories (like "Pornography")—not just posture or app controls.&lt;/P&gt;&lt;P&gt;Go to Security Profiles and verify the profile type (e.g., “Mobile Web” or “Full Mobile”) includes content filtering.&lt;/P&gt;&lt;P&gt;Incompatible profiles (like posture-only) can't enforce URL category restrictions, and the rule creation will silently fail.&lt;/P&gt;&lt;P&gt;2. Rule Conditions &amp;amp; Ordering&lt;BR /&gt;Your rule might be conflicting with higher-priority rules. Web policies are evaluated top-down, and a matching generic rule may block creation of a more specific one.&lt;/P&gt;&lt;P&gt;Ensure your mobile-specific rule is at the top of the list or above any more general rules.&lt;/P&gt;&lt;P&gt;Double-check that:&lt;/P&gt;&lt;P&gt;"From" is correctly scoped to mobile devices (e.g., iOS/Android).&lt;/P&gt;&lt;P&gt;"To" uses valid category names (like “Pornography”).&lt;/P&gt;&lt;P&gt;Action (Block/Allow) and the selected security profile match the traffic type (e.g., web).&lt;/P&gt;&lt;P&gt;3. Advanced Enforcement Settings&lt;BR /&gt;Sometimes, advanced options must be either disabled or corrected to allow the rule creation.&lt;/P&gt;&lt;P&gt;In the Advanced section of the Security Profile, ensure web features (URL filtering, decryption, IPS, etc.) are enabled&lt;BR /&gt;&lt;A href="https://docs.sse.cisco.com/sse-user-guide/docs/troubleshoot-internet-access-rules?utm_source=chatgpt.com" target="_blank"&gt;https://docs.sse.cisco.com/sse-user-guide/docs/troubleshoot-internet-access-rules?utm_source=chatgpt.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Temporarily disable IPS or decryption to test rule creation—if it succeeds, you’ve pinpointed a missing feature in the profile.&lt;/P&gt;&lt;P&gt;4. Validation Error Messages&lt;BR /&gt;More recent versions of Cisco Secure (Umbrella/SSE) might display a generic error message even when something deeper is wrong (like missing permissions or invalid traffic selection).&lt;/P&gt;&lt;P&gt;Review the browser dev console to see if there's a validation error suppressed by the UI.&lt;/P&gt;&lt;P&gt;Also review policy logs to see if your rule was partially accepted and then rejected.&lt;/P&gt;&lt;P&gt;What To Do Next&lt;BR /&gt;Open the Mobile Security Profile and confirm category filtering is enabled.&lt;/P&gt;&lt;P&gt;In Internet Access, click Advanced settings:&lt;/P&gt;&lt;P&gt;Enable “Web features” and “Decryption” temporarily to allow rule creation.&lt;/P&gt;&lt;P&gt;Move your “Mobile Device Global Block” rule to the top, then save again.&lt;/P&gt;&lt;P&gt;If it still fails:&lt;/P&gt;&lt;P&gt;Create an Allow rule for the same “Roaming iOS/Android → Pornography” combination. If that fails too, it's almost certainly a profile limitation.&lt;/P&gt;&lt;P&gt;Inspect developer console for hidden validation errors.&lt;/P&gt;</description>
    <pubDate>Fri, 27 Jun 2025 18:13:35 GMT</pubDate>
    <dc:creator>wajidhassan</dc:creator>
    <dc:date>2025-06-27T18:13:35Z</dc:date>
    <item>
      <title>Cisco Secure Access Policy for Mobile Devices</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-secure-access-policy-for-mobile-devices/m-p/5264352#M8752</link>
      <description>&lt;P&gt;I am trying to create an access policy for just mobile devices, that will block certain content categories that are different from macOS/Windows devices.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have the macOS/Windows policies such as our global allow and global block applied to just those devices. However, when I navigate to Secure &amp;gt; Access Policy &amp;gt; Add Rule &amp;gt; Internet Access and create the policy, I built the policy with the following settings:&lt;/P&gt;&lt;P&gt;Name- Mobile Device Global Block, Specify Access- Block, From- Roaming devices Any iOS/ Android device, To- Pornography&lt;/P&gt;&lt;P&gt;Then I select a security profile that was built for mobile devices, and select save. I immediately get the Rule wasn't created error.&lt;/P&gt;&lt;P&gt;I try again with an allow policy which is the same steps as above, but with the change of Allow is selected vs Block, and again the same error.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I get no info on why it isn't created, how can I fix this or troubleshoot why it isn't working?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Hank&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2025-02-24_13-03-31.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/240490iF233AFB005904149/image-size/medium?v=v2&amp;amp;px=400" role="button" title="2025-02-24_13-03-31.png" alt="2025-02-24_13-03-31.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Feb 2025 18:06:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-secure-access-policy-for-mobile-devices/m-p/5264352#M8752</guid>
      <dc:creator>hank hale</dc:creator>
      <dc:date>2025-02-24T18:06:39Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Secure Access Policy for Mobile Devices</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-secure-access-policy-for-mobile-devices/m-p/5303496#M8892</link>
      <description>&lt;P&gt;Make sure the security profile you’re assigning to that rule actually supports web content categories (like "Pornography")—not just posture or app controls.&lt;/P&gt;&lt;P&gt;Go to Security Profiles and verify the profile type (e.g., “Mobile Web” or “Full Mobile”) includes content filtering.&lt;/P&gt;&lt;P&gt;Incompatible profiles (like posture-only) can't enforce URL category restrictions, and the rule creation will silently fail.&lt;/P&gt;&lt;P&gt;2. Rule Conditions &amp;amp; Ordering&lt;BR /&gt;Your rule might be conflicting with higher-priority rules. Web policies are evaluated top-down, and a matching generic rule may block creation of a more specific one.&lt;/P&gt;&lt;P&gt;Ensure your mobile-specific rule is at the top of the list or above any more general rules.&lt;/P&gt;&lt;P&gt;Double-check that:&lt;/P&gt;&lt;P&gt;"From" is correctly scoped to mobile devices (e.g., iOS/Android).&lt;/P&gt;&lt;P&gt;"To" uses valid category names (like “Pornography”).&lt;/P&gt;&lt;P&gt;Action (Block/Allow) and the selected security profile match the traffic type (e.g., web).&lt;/P&gt;&lt;P&gt;3. Advanced Enforcement Settings&lt;BR /&gt;Sometimes, advanced options must be either disabled or corrected to allow the rule creation.&lt;/P&gt;&lt;P&gt;In the Advanced section of the Security Profile, ensure web features (URL filtering, decryption, IPS, etc.) are enabled&lt;BR /&gt;&lt;A href="https://docs.sse.cisco.com/sse-user-guide/docs/troubleshoot-internet-access-rules?utm_source=chatgpt.com" target="_blank"&gt;https://docs.sse.cisco.com/sse-user-guide/docs/troubleshoot-internet-access-rules?utm_source=chatgpt.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Temporarily disable IPS or decryption to test rule creation—if it succeeds, you’ve pinpointed a missing feature in the profile.&lt;/P&gt;&lt;P&gt;4. Validation Error Messages&lt;BR /&gt;More recent versions of Cisco Secure (Umbrella/SSE) might display a generic error message even when something deeper is wrong (like missing permissions or invalid traffic selection).&lt;/P&gt;&lt;P&gt;Review the browser dev console to see if there's a validation error suppressed by the UI.&lt;/P&gt;&lt;P&gt;Also review policy logs to see if your rule was partially accepted and then rejected.&lt;/P&gt;&lt;P&gt;What To Do Next&lt;BR /&gt;Open the Mobile Security Profile and confirm category filtering is enabled.&lt;/P&gt;&lt;P&gt;In Internet Access, click Advanced settings:&lt;/P&gt;&lt;P&gt;Enable “Web features” and “Decryption” temporarily to allow rule creation.&lt;/P&gt;&lt;P&gt;Move your “Mobile Device Global Block” rule to the top, then save again.&lt;/P&gt;&lt;P&gt;If it still fails:&lt;/P&gt;&lt;P&gt;Create an Allow rule for the same “Roaming iOS/Android → Pornography” combination. If that fails too, it's almost certainly a profile limitation.&lt;/P&gt;&lt;P&gt;Inspect developer console for hidden validation errors.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jun 2025 18:13:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-secure-access-policy-for-mobile-devices/m-p/5303496#M8892</guid>
      <dc:creator>wajidhassan</dc:creator>
      <dc:date>2025-06-27T18:13:35Z</dc:date>
    </item>
  </channel>
</rss>

