The application command configures applications to which a security policy rule applies.
The undo application command deletes applications to which a security policy rule applies.
application { any | app app-name &<1-6> | app-group app-group-name &<1-6> | category category-name [ sub-category sub-category-name &<1-6> ] | label label-name &<1-6> | software software-name &<1-6> }
undo application { all | app app-name &<1-6> | app-group app-group-name &<1-6> | category category-name [ sub-category sub-category-name &<1-6> ] | label label-name &<1-6> | software software-name &<1-6> }
| Parameter | Description | Value |
|---|---|---|
| any | Indicates all applications to which a security policy rule applies. | - |
| app app-name &<1-6> | Indicates the application to which a security policy rule applies. | The specified application must exist. You can add or delete a maximum of six applications at a time. |
| app-group app-group-name &<1-6> | Indicates the application group to which a security policy rule applies. | The specified application group must exist. You can add or delete a maximum of six application groups at a time. |
| category category-name | Indicates the category to which a security policy rule applies. | The specified category must exist. |
| sub-category sub-category-name &<1-6> | Indicates the sub-category to which a security policy rule applies. | The sub-category must exist. A maximum of six sub-categories can be added to or deleted from a security policy rule at a time. |
| label label-name &<1-6> | Indicates an application label to which a security policy rule applies. | The specified application label must already exist. You can add or delete a maximum of six application labels at a time. |
| software software-name &<1-6> | Specifies the software name referenced by the security policy rule. | The value must be an existing software name. You can add or delete a maximum of six software programs at a time. |
| all | Deletes all applications to which a security policy rule applies. | - |
The applications of security policy rules can belong to predefined or user-defined application categories. You can run the user-defined-application name command to create user-defined application categories.
# Apply security policy rule policy_sec to application QQDownLoad.
<sysname> system-view [sysname] security-policy [sysname-policy-security] rule name policy_sec [sysname-policy-security-rule-policy_sec] application app QQDownLoad
# Set the application software to eSpace in security policy rule policy_sec.
<sysname> system-view [sysname] security-policy [sysname-policy-security] rule name policy_sec [sysname-policy-security-rule-policy_sec] application software eSpace