Deployment Example 1: Access Manager 7.0 Load Balancing, Distributed Authentication UI, and Session Failover

ProcedureTo Create a Test Policy in the User Realm

  1. In the Access Manager 1 console, on the Access Control tab, click the users link.

  2. Click the Policies tab.

  3. Under Policies, click New Policy.

  4. In the Name field, enter URL Policy for ApplicationServer-1.

  5. Under Rules, click New.

  6. On the page “Step 1 of 2: Select Service Type for the Rule,” click Next.

    The default “URL Policy Agent (with resource name)” should be selected.

  7. On the page “Step 2 of 2: New Rule,” provide the following information:

    Name:

    agentsample

    Parent Resource Name:

    In the list, select http://ProtectedResource-1.example.com:1081/agentsample/*

    Resource Name:

    The following is automatically entered when you select the Parent Resource Name above:

    http://ProtectedResource-1.example.com:1081/agentsample/*

    GET

    Mark this check box, and verify that the Allow value is selected.

    POST

    Mark this check box, and verify that the Allow value is selected.

  8. Click Finish.

    The rule agentsample is now added to the list of Rules.

  9. Under Subjects, click New.

  10. On the page “Step 1 of 2: Select Subject Type,” select Access Manager Identity Subject, then click Next.

  11. On the page “ Step 2 of 2: New Subject — Access Manager Identity Subject,” provide the following information:

    Name:

    agentsampleRoles

    Filter:

    Select role.

  12. Click Search.

  13. In the Available list, the select manager and employee roles, and then click Add.

    The roles are now displayed in the Selected list.

  14. Click Finish.

  15. Click Create.

    The new policy is included in the list of Policies.