I am having a hard time setting up a granular policy for the microbranch. I followed techdocs esp-sd-branch-deploy-100-L3-Microbranch (Optional) Routed Layer 3 Full-Tunnel Configuration (see below), without success
https://www.arubanetworks.com/techdocs/VSG/docs/080-sd-branch-deploy/esp-sd-branch-deploy-100-L3-Microbranch/#optional-routed-layer-3-full-tunnel-configuration
What keeps happening is that despite defining that only certain applications are allowed everything is still able to pass though except for ICMP echo.
I defined a PBR policy
In the PBR policy I added two datacenter subnets
I defined a policy for the SSID I was testing
I also changed per the document the tunnels & routing datacenter settings.
I am running the correct code.
With these settings, users of the SSID are still able to browse the internet. What I wanted to achieve is that users would be able to access datacenter servers as well as use Microsoft Teams, but not be able to browse the internet. Is this possible? What am I doing wrong?
------------------------------
Martijn van Overbeek
Architect, Netcraftsmen a BlueAlly Company
------------------------------