About Deploying Policies

Deploying a policy is the act of transferring the policy from the CMP database to an MPE device. After a policy is deployed, the rules defined within the policy are used as decision-making criteria by the MPE device.

Figure 12 shows how policies P1 through P7 are created in the CMP database and then deployed individually to different MPE devices within the network. Each of the policies is associated individually with the MPE device to which it is deployed. In the example, each policy server (MPE device) displays the policies that have been deployed to it and the order in which they are applied to policy requests, from top to bottom.

Policy Deployment

Figure 12 shows how the same library of policies can be grouped first and then deployed as policy groups. When a policy group is created, the policies are arranged in the order in which they are to be evaluated. Grouping policies makes deployment of multiple policies easier and helps to ensure consistency in how policies are applied to policy requests on different MPE devices.

Policy Group Deployment

When you first create a policy rule, that rule exists only within the CMP database. After the policy rule is deployed, the policy rule is automatically redeployed when you make any changes. Automatic redeployment also applies to policy groups: any change to a policy group triggers automatic redeployment. If a policy group is deployed to one or more MPE devices and you add a new policy rule to the policy group, the rule is automatically deployed to those MPE devices.

Figure 3 shows that when a policy (P3) is modified, its associated groups (PG-1 and PG-3) are redeployed automatically.

Policy Redeployment

You do not need to deploy policy rules that are referenced by other deployed policy rules or policy groups. Reference policies are automatically deployed when called by the parent policy.