Skip to content

Policy Assignment and Activation

Policy assignment is the controlled handoff between engineering intent and operational enforcement. Policy Profile Composer creates and saves the complete, ordered policy file; Service Management assigns that profile to the L2Proxy service that will enforce it.

End-to-end handoff

Access Policies reviewed
Policy Profile assembled and saved
Policy Profile selected in Service Profile
Protected access path confirmed
Service Profile saved
Independent L2Proxy instance started or restarted
Policy active on industrial traffic

Policy package handoff from engineering artifacts to enforcement points

Figure — Policy assignment preserves end-to-end handoff from package to enforcement point.

The saved Policy Profile appears in Service Management as managed policy content. It is shown separately from other standalone rule files, helping the operator select the reviewed output of the policy workflow.

Before activation, confirm:

  1. The Service Profile has a clear industrial purpose and owner.
  2. The correct Policy Profile and revision were approved.
  3. The protected user or industrial path is correct.
  4. Expected equipment and operations are present in the policy.
  5. Unexpected or unsafe commands have the intended response.
  6. Event recording and archive settings match the customer's evidence requirements.
  7. Normal, denied, and abnormal cases were validated.
  8. The change and rollback decision were approved.

Activation choices

Action Industrial use
Start Activate a configured protection service
Stop Remove that service from operation under an approved procedure
Restart Reload a revised operating or Policy Profile for the independent service
View log Confirm startup, diagnose a service issue, or review local operating evidence

Each action applies to the selected instance, allowing a customer to maintain one access path without interrupting unrelated L2Proxy services.

Policy revision without ambiguity

  • An Access Policy revision changes one decision.
  • A Policy Profile revision changes the complete policy set assigned to a service.
  • A Service Profile save changes the operating assignment.
  • A service restart activates the approved revision for that instance.

This provides a traceable chain from industrial requirement to active enforcement and supports deliberate rollback to the previously approved combination when required.

Evidence of effective protection

After activation, the customer can confirm:

  • that the intended service is running;
  • which Policy Profile the Service Profile references;
  • whether representative permitted operations are accepted;
  • whether representative violations are blocked or recorded as approved;
  • whether inspection and rule-decision events reach the event archive;
  • whether the local service log remains available for troubleshooting.

Next: Multi-Instance Operations.