{"id":22853,"date":"2023-02-03T01:45:00","date_gmt":"2023-02-03T01:45:00","guid":{"rendered":"https:\/\/nsfocusglobal.com\/?p=22853"},"modified":"2026-04-17T18:07:42","modified_gmt":"2026-04-17T18:07:42","slug":"nips-v5-6r10-policy-matching-mechanism","status":"publish","type":"post","link":"https:\/\/nsfocusglobal.com\/pt-br\/nips-v5-6r10-policy-matching-mechanism\/","title":{"rendered":"NIPS V5.6R10 Policy Matching Mechanism"},"content":{"rendered":"<!DOCTYPE html PUBLIC \"-\/\/W3C\/\/DTD HTML 4.0 Transitional\/\/EN\" \"http:\/\/www.w3.org\/TR\/REC-html40\/loose.dtd\">\n<html><body><p>The NIPS policy matching mechanism is blocking first. That is, when traffic is matched against all policies, if one policy is matched whose action is set to <strong>block<\/strong>, traffic is blocked.<\/p>\n\n\n\n<p>When configuring IPS policies, it is recommended that they should not be overlapped. For example, security zones should not be overlapped, and address objects should not have intersections. If policy overlapping occurs, data packets may match two policies simultaneously, thus causing failure to achieve the intended goal. The following shows several configuration errors and how to correct them.<\/p>\n\n\n\n<p>1.  Configure an IP address whitelist whose action is set to unblock. Packets from the remaining IP addresses are blocked.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><a href=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/1-4.png\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"129\" src=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/1-4-1024x129.png\" alt=\"Red circular no entry sign with a white horizontal bar.\" class=\"wp-image-22854\" srcset=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/1-4-1024x129.png 1024w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/1-4-300x38.png 300w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/1-4-768x97.png 768w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/1-4-1536x194.png 1536w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/1-4-600x76.png 600w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/1-4-200x25.png 200w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/1-4.png 1728w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/a><\/figure>\n<\/div>\n\n\n<p>Problem description:<\/p>\n\n\n\n<p>Policy 2 is configured to permit packets from the IP segment in the whitelist to pass, and policy 1 is configured to block packets from the remaining IP segment. However, it is found that all IP addresses are matched against policy 1.<\/p>\n\n\n\n<p>Solution:<\/p>\n\n\n\n<p>Invert the IP segment in policy 1 to achieve the effect of whitelist configuration, as shown below.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><a href=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/2-3.png\"><img decoding=\"async\" width=\"1024\" height=\"161\" src=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/2-3-1024x161.png\" alt=\"Red circular no entry sign with a white horizontal bar.\" class=\"wp-image-22856\" srcset=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/2-3-1024x161.png 1024w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/2-3-300x47.png 300w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/2-3-768x121.png 768w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/2-3-1536x242.png 1536w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/2-3-600x95.png 600w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/2-3-200x32.png 200w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/2-3.png 1732w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/a><\/figure>\n<\/div>\n\n\n<p>2.  A false positive is generated due to a specified rule, so a whitelist is configured to permit packets from specified IP addresses to pass.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><a href=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/3-5.png\"><img decoding=\"async\" width=\"1024\" height=\"110\" src=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/3-5-1024x110.png\" alt=\"Red circular no entry sign with a white horizontal bar.\" class=\"wp-image-22858\" srcset=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/3-5-1024x110.png 1024w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/3-5-300x32.png 300w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/3-5-768x82.png 768w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/3-5-1536x165.png 1536w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/3-5-600x64.png 600w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/3-5-200x21.png 200w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/3-5.png 1727w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/a><\/figure>\n<\/div>\n\n\n<p>Problem description:<\/p>\n\n\n\n<p>A policy is configured not to match IP addresses in the whitelist against rule 10000. However, IP addresses in this whitelist are still matched with rule 10000.<\/p>\n\n\n\n<p>Solution:<\/p>\n\n\n\n<p>Add an exception rule as follows:<\/p>\n\n\n\n<p>(1)  Choose <strong>Object<\/strong> &gt; <strong>Rule<\/strong> &gt; <strong>Exception Rule<\/strong>, and click <strong>New<\/strong>.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><a href=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/4-2.png\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"350\" src=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/4-2-1024x350.png\" alt=\"Red circular no entry sign with a white horizontal bar.\" class=\"wp-image-22860\" srcset=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/4-2-1024x350.png 1024w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/4-2-300x103.png 300w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/4-2-768x263.png 768w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/4-2-1536x526.png 1536w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/4-2-600x205.png 600w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/4-2-200x68.png 200w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/4-2.png 1917w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/a><\/figure>\n<\/div>\n\n\n<p>(2)  Configure an exception rule, click <strong>OK<\/strong>, and then click <strong>Apply Settings<\/strong> to save settings.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><a href=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/5-1.png\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"400\" src=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/5-1-1024x400.png\" alt=\"Red circular no entry sign with a white horizontal bar.\" class=\"wp-image-22862\" srcset=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/5-1-1024x400.png 1024w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/5-1-300x117.png 300w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/5-1-768x300.png 768w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/5-1-1536x600.png 1536w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/5-1-600x234.png 600w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/5-1-200x78.png 200w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/5-1.png 1919w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/a><\/figure>\n<\/div>\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large is-resized\"><a href=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/6-1.png\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/6-1-1024x317.png\" alt=\"Red circular no entry sign with a white horizontal bar.\" class=\"wp-image-22864\" width=\"840\" height=\"260\" srcset=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/6-1-1024x317.png 1024w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/6-1-300x93.png 300w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/6-1-768x238.png 768w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/6-1-1536x475.png 1536w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/6-1-600x186.png 600w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/6-1-200x62.png 200w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/6-1.png 1732w\" sizes=\"(max-width: 840px) 100vw, 840px\" \/><\/a><\/figure>\n<\/div>\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><a href=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/s.png\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"296\" src=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/s-1024x296.png\" alt=\"Red circular no entry sign with a white horizontal bar.\" class=\"wp-image-22868\" srcset=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/s-1024x296.png 1024w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/s-300x87.png 300w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/s-768x222.png 768w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/s-1536x444.png 1536w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/s-600x173.png 600w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/s-200x58.png 200w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/s.png 1920w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/a><\/figure>\n<\/div>\n\n\n<p><strong>Description<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Rule ID: ID of the exception rule. This ID must be the same as the ID of the related intrusion prevention rule.<\/li><li>Source IP: Specifies the source IP address or IP segment, that is, the valid range of IP addresses to be covered by this exception rule. Only packets from the specified source IP address or IP segment are allowed to pass.<\/li><li>Destination IP: Specifies the destination IP address or IP segment, that is, the valid range of IP addresses to be covered by this exception rule. Only packets to the specified destination IP address or IP segment are allowed to pass.<\/li><\/ul>\n\n\n\n<p>3.  When adding more than one IP segment whitelist, add all IP segments to a group address object and invert the group address object instead of a single IP address segment.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><a href=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/8-1.png\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"238\" src=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/8-1-1024x238.png\" alt=\"Red circular no entry sign with a white horizontal bar.\" class=\"wp-image-22870\" srcset=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/8-1-1024x238.png 1024w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/8-1-300x70.png 300w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/8-1-768x179.png 768w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/8-1-1536x357.png 1536w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/8-1-600x139.png 600w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/8-1-200x46.png 200w, https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/01\/8-1.png 1910w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/a><\/figure>\n<\/div>\n\n\n<p>Note that when configuring multiple intrusion prevention policies on IPS, if security zones are overlapped, address objects must not have intersections.<\/p>\n<\/body><\/html>\n","protected":false},"excerpt":{"rendered":"<p>The NIPS policy matching mechanism is blocking first. That is, when traffic is matched against all policies, if one policy is matched whose action is set to block, traffic is blocked. When configuring IPS policies, it is recommended that they should not be overlapped. For example, security zones should not be overlapped, and address objects [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":35721,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_coblocks_attr":"","_coblocks_dimensions":"","_coblocks_responsive_height":"","_coblocks_accordion_ie_support":"","footnotes":""},"categories":[10],"tags":[487],"class_list":["post-22853","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-nips","tag-knowledge-base"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>NIPS V5.6R10 Policy Matching Mechanism - NSFOCUS<\/title>\n<meta name=\"robots\" content=\"noindex, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<meta property=\"og:locale\" content=\"pt_BR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"NIPS V5.6R10 Policy Matching Mechanism - NSFOCUS\" \/>\n<meta property=\"og:description\" content=\"The NIPS policy matching mechanism is blocking first. That is, when traffic is matched against all policies, if one policy is matched whose action is set\" \/>\n<meta property=\"og:url\" content=\"https:\/\/nsfocusglobal.com\/nips-v5-6r10-policy-matching-mechanism\/\" \/>\n<meta property=\"og:site_name\" content=\"NSFOCUS\" \/>\n<meta property=\"article:published_time\" content=\"2023-02-03T01:45:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-04-17T18:07:42+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/02\/1-4-1024x129-1.png\" \/>\n<meta name=\"author\" content=\"admin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:title\" content=\"NIPS V5.6R10 Policy Matching Mechanism - NSFOCUS\" \/>\n<meta name=\"twitter:description\" content=\"The NIPS policy matching mechanism is blocking first. That is, when traffic is matched against all policies, if one policy is matched whose action is set\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/02\/1-4-1024x129-1.png\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"admin\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. tempo de leitura\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/nips-v5-6r10-policy-matching-mechanism\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/nips-v5-6r10-policy-matching-mechanism\\\/\"},\"author\":{\"name\":\"admin\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/pt-br\\\/#\\\/schema\\\/person\\\/fd9ab61c9c77a81bbd870f725cc0c61d\"},\"headline\":\"NIPS V5.6R10 Policy Matching Mechanism\",\"datePublished\":\"2023-02-03T01:45:00+00:00\",\"dateModified\":\"2026-04-17T18:07:42+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/nips-v5-6r10-policy-matching-mechanism\\\/\"},\"wordCount\":408,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/pt-br\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/nips-v5-6r10-policy-matching-mechanism\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/nsfocusglobal.com\\\/wp-content\\\/uploads\\\/2023\\\/02\\\/1-4-1024x129-1.png\",\"keywords\":[\"knowledge base;\"],\"articleSection\":[\"NIPS\"],\"inLanguage\":\"pt-BR\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/nsfocusglobal.com\\\/nips-v5-6r10-policy-matching-mechanism\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/nips-v5-6r10-policy-matching-mechanism\\\/\",\"url\":\"https:\\\/\\\/nsfocusglobal.com\\\/nips-v5-6r10-policy-matching-mechanism\\\/\",\"name\":\"NIPS V5.6R10 Policy Matching Mechanism - NSFOCUS\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/pt-br\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/nips-v5-6r10-policy-matching-mechanism\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/nips-v5-6r10-policy-matching-mechanism\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/nsfocusglobal.com\\\/wp-content\\\/uploads\\\/2023\\\/02\\\/1-4-1024x129-1.png\",\"datePublished\":\"2023-02-03T01:45:00+00:00\",\"dateModified\":\"2026-04-17T18:07:42+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/nips-v5-6r10-policy-matching-mechanism\\\/#breadcrumb\"},\"inLanguage\":\"pt-BR\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/nsfocusglobal.com\\\/nips-v5-6r10-policy-matching-mechanism\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"pt-BR\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/nips-v5-6r10-policy-matching-mechanism\\\/#primaryimage\",\"url\":\"https:\\\/\\\/nsfocusglobal.com\\\/wp-content\\\/uploads\\\/2023\\\/02\\\/1-4-1024x129-1.png\",\"contentUrl\":\"https:\\\/\\\/nsfocusglobal.com\\\/wp-content\\\/uploads\\\/2023\\\/02\\\/1-4-1024x129-1.png\",\"width\":1024,\"height\":129,\"caption\":\"Table with data and protection mode options.\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/nips-v5-6r10-policy-matching-mechanism\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/nsfocusglobal.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"NIPS V5.6R10 Policy Matching Mechanism\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/pt-br\\\/#website\",\"url\":\"https:\\\/\\\/nsfocusglobal.com\\\/pt-br\\\/\",\"name\":\"NSFOCUS\",\"description\":\"Security Made Smart and Simple\",\"publisher\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/pt-br\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/nsfocusglobal.com\\\/pt-br\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"pt-BR\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/pt-br\\\/#organization\",\"name\":\"NSFOCUS\",\"url\":\"https:\\\/\\\/nsfocusglobal.com\\\/pt-br\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"pt-BR\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/pt-br\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/nsfocusglobal.com\\\/wp-content\\\/uploads\\\/2024\\\/08\\\/logo-ns.png\",\"contentUrl\":\"https:\\\/\\\/nsfocusglobal.com\\\/wp-content\\\/uploads\\\/2024\\\/08\\\/logo-ns.png\",\"width\":248,\"height\":36,\"caption\":\"NSFOCUS\"},\"image\":{\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/pt-br\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/nsfocusglobal.com\\\/pt-br\\\/#\\\/schema\\\/person\\\/fd9ab61c9c77a81bbd870f725cc0c61d\",\"name\":\"admin\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"pt-BR\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/d3dc987908fc59791d261b1006d84eb931d15287261476b9384e690ed0c568de?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/d3dc987908fc59791d261b1006d84eb931d15287261476b9384e690ed0c568de?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/d3dc987908fc59791d261b1006d84eb931d15287261476b9384e690ed0c568de?s=96&d=mm&r=g\",\"caption\":\"admin\"},\"sameAs\":[\"https:\\\/\\\/nsfocusglobal.com\"],\"url\":\"https:\\\/\\\/nsfocusglobal.com\\\/pt-br\\\/author\\\/admin\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"NIPS V5.6R10 Policy Matching Mechanism - NSFOCUS","robots":{"index":"noindex","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"og_locale":"pt_BR","og_type":"article","og_title":"NIPS V5.6R10 Policy Matching Mechanism - NSFOCUS","og_description":"The NIPS policy matching mechanism is blocking first. That is, when traffic is matched against all policies, if one policy is matched whose action is set","og_url":"https:\/\/nsfocusglobal.com\/nips-v5-6r10-policy-matching-mechanism\/","og_site_name":"NSFOCUS","article_published_time":"2023-02-03T01:45:00+00:00","article_modified_time":"2026-04-17T18:07:42+00:00","og_image":[{"url":"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/02\/1-4-1024x129-1.png","type":"","width":"","height":""}],"author":"admin","twitter_card":"summary_large_image","twitter_title":"NIPS V5.6R10 Policy Matching Mechanism - NSFOCUS","twitter_description":"The NIPS policy matching mechanism is blocking first. That is, when traffic is matched against all policies, if one policy is matched whose action is set","twitter_image":"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/02\/1-4-1024x129-1.png","twitter_misc":{"Escrito por":"admin","Est. tempo de leitura":"4 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/nsfocusglobal.com\/nips-v5-6r10-policy-matching-mechanism\/#article","isPartOf":{"@id":"https:\/\/nsfocusglobal.com\/nips-v5-6r10-policy-matching-mechanism\/"},"author":{"name":"admin","@id":"https:\/\/nsfocusglobal.com\/pt-br\/#\/schema\/person\/fd9ab61c9c77a81bbd870f725cc0c61d"},"headline":"NIPS V5.6R10 Policy Matching Mechanism","datePublished":"2023-02-03T01:45:00+00:00","dateModified":"2026-04-17T18:07:42+00:00","mainEntityOfPage":{"@id":"https:\/\/nsfocusglobal.com\/nips-v5-6r10-policy-matching-mechanism\/"},"wordCount":408,"commentCount":0,"publisher":{"@id":"https:\/\/nsfocusglobal.com\/pt-br\/#organization"},"image":{"@id":"https:\/\/nsfocusglobal.com\/nips-v5-6r10-policy-matching-mechanism\/#primaryimage"},"thumbnailUrl":"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/02\/1-4-1024x129-1.png","keywords":["knowledge base;"],"articleSection":["NIPS"],"inLanguage":"pt-BR","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/nsfocusglobal.com\/nips-v5-6r10-policy-matching-mechanism\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/nsfocusglobal.com\/nips-v5-6r10-policy-matching-mechanism\/","url":"https:\/\/nsfocusglobal.com\/nips-v5-6r10-policy-matching-mechanism\/","name":"NIPS V5.6R10 Policy Matching Mechanism - NSFOCUS","isPartOf":{"@id":"https:\/\/nsfocusglobal.com\/pt-br\/#website"},"primaryImageOfPage":{"@id":"https:\/\/nsfocusglobal.com\/nips-v5-6r10-policy-matching-mechanism\/#primaryimage"},"image":{"@id":"https:\/\/nsfocusglobal.com\/nips-v5-6r10-policy-matching-mechanism\/#primaryimage"},"thumbnailUrl":"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/02\/1-4-1024x129-1.png","datePublished":"2023-02-03T01:45:00+00:00","dateModified":"2026-04-17T18:07:42+00:00","breadcrumb":{"@id":"https:\/\/nsfocusglobal.com\/nips-v5-6r10-policy-matching-mechanism\/#breadcrumb"},"inLanguage":"pt-BR","potentialAction":[{"@type":"ReadAction","target":["https:\/\/nsfocusglobal.com\/nips-v5-6r10-policy-matching-mechanism\/"]}]},{"@type":"ImageObject","inLanguage":"pt-BR","@id":"https:\/\/nsfocusglobal.com\/nips-v5-6r10-policy-matching-mechanism\/#primaryimage","url":"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/02\/1-4-1024x129-1.png","contentUrl":"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2023\/02\/1-4-1024x129-1.png","width":1024,"height":129,"caption":"Table with data and protection mode options."},{"@type":"BreadcrumbList","@id":"https:\/\/nsfocusglobal.com\/nips-v5-6r10-policy-matching-mechanism\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/nsfocusglobal.com\/"},{"@type":"ListItem","position":2,"name":"NIPS V5.6R10 Policy Matching Mechanism"}]},{"@type":"WebSite","@id":"https:\/\/nsfocusglobal.com\/pt-br\/#website","url":"https:\/\/nsfocusglobal.com\/pt-br\/","name":"NSFOCUS","description":"Security Made Smart and Simple","publisher":{"@id":"https:\/\/nsfocusglobal.com\/pt-br\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/nsfocusglobal.com\/pt-br\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"pt-BR"},{"@type":"Organization","@id":"https:\/\/nsfocusglobal.com\/pt-br\/#organization","name":"NSFOCUS","url":"https:\/\/nsfocusglobal.com\/pt-br\/","logo":{"@type":"ImageObject","inLanguage":"pt-BR","@id":"https:\/\/nsfocusglobal.com\/pt-br\/#\/schema\/logo\/image\/","url":"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/08\/logo-ns.png","contentUrl":"https:\/\/nsfocusglobal.com\/wp-content\/uploads\/2024\/08\/logo-ns.png","width":248,"height":36,"caption":"NSFOCUS"},"image":{"@id":"https:\/\/nsfocusglobal.com\/pt-br\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/nsfocusglobal.com\/pt-br\/#\/schema\/person\/fd9ab61c9c77a81bbd870f725cc0c61d","name":"admin","image":{"@type":"ImageObject","inLanguage":"pt-BR","@id":"https:\/\/secure.gravatar.com\/avatar\/d3dc987908fc59791d261b1006d84eb931d15287261476b9384e690ed0c568de?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/d3dc987908fc59791d261b1006d84eb931d15287261476b9384e690ed0c568de?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/d3dc987908fc59791d261b1006d84eb931d15287261476b9384e690ed0c568de?s=96&d=mm&r=g","caption":"admin"},"sameAs":["https:\/\/nsfocusglobal.com"],"url":"https:\/\/nsfocusglobal.com\/pt-br\/author\/admin\/"}]}},"_links":{"self":[{"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/posts\/22853","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/comments?post=22853"}],"version-history":[{"count":0,"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/posts\/22853\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/media\/35721"}],"wp:attachment":[{"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/media?parent=22853"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/categories?post=22853"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/nsfocusglobal.com\/pt-br\/wp-json\/wp\/v2\/tags?post=22853"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}