In the parameters area, for Country in country group, select the Blacklisted Click Apply.

10-54 Oracle Fusion Middleware Administrators Guide for Oracle Adaptive Access Manager

f. Click OK to dismiss the confirmation dialog.

7. Configure the policy to run for all users.

a. Click the Group Linking tab.

b. For Run Mode, select All Users.

Since All Users is selected for the run mode, the policy is executed run for all users. Specifying a run mode is a mandatory step in order for the policy to execute. It enables the policy to executerun for a set of users or all users. For information, see Section 10.9, Linking Policy to All Users or a User ID Group.

c. Click Apply.

A confirmation dialog displays the status of the operation.

d. Click OK to dismiss the confirmation dialog.

8. Create IP Excessive Use rule for the policy.

a. Click the Rules tab.

b. In the Rules tab, click Add to add a new rule.

The New Rule page is displayed. c. In the Summary tab, enter IP Excessive Use as the rule name. d. Enter a description for the rule.

e. Select Active as the rule status.

f. Add the Location: IP excessive use rule condition to create the new rule.

a. To add the Location: IP excessive use condition, click the Conditions tab.

b. In the Conditions tab, click Add. The Add Condition page appears.

c. Search for the Location: IP excessive use condition by entering IP in the

Condition Name field and then clicking Search.

d. In the Search Results table, select that condition and click OK.

e. In the New RuleIP page, select Location: IP excessive use in the top

panel. The bottom panel displays the parameters of the condition. f. In the bottom panel, modify the parameters. Enter 10 for Number of Users. Select 1 for Within hours. Enter 0 for and not used in days. 9. Create the Location: IP in Group rule for the policy. a. Click the Rules tab in the Policy Details page. b. In the Rules tab, click Add to add a new rule. The New Rule page is displayed.

c. In the Summary tab, enter IP in Group as the rule name.

d. Enter a description for the rule.

e. Select Active as the rule status.

Managing Policies, Rules, and Conditions 10-55

f. Add the Location: IP in Group rule condition to create the new rule.

a. To add the Location: IP in Group condition, click the Conditions tab.

b. In the Conditions tab, click Add. The Add Condition page appears.

c. Search for the Location: IP in Group condition by entering IP in the

Condition Name field and then clicking Search.

d. In the Search Results table, select that condition and click OK.

e. In the New RuleIP page, select Location: IP in Group in the top panel.

The bottom panel displays the parameters of the condition. f. In the bottom panel, modify the parameters. Select true for Is in List. Select the Monitor IPs group.

10. Create a trigger combination in which if both conditions are true, trigger the Block

action and the IP Surge Alert. 1. In the Policy Details page, click the Trigger Combination tab. 2. Click the Add button. 3. For the IP Excessive Use, select True. 4. For the IP in Group, select True. 5. For Action Group, select Block. 6. For Alert Group, select IP Surge High Alert. 7. Click Apply.

10.34.14 Use Case: Canceling Rule Creation

William is a Security Administrator and he creates a new policy. He is not sure which rule condition would apply for his business use case. Hence he decides to close the rule without adding any condition. 1. Log in to OAAM Admin as an administrator.

2. In the Navigation tree, double-click Policies.

3. In the Policies Search page, click the New Policy button.

4. Create a new policy.

5. In the Policy Details page, click the Rules tab.

6. In the Rules tab, click Add to add a new rule.

The New Rule page is displayed. 7. Enter the rule name. 8. Enter a description for the rule.

9. To add the condition, click the Conditions tab.

10. In the Conditions tab, click Add. The Add Condition page appears.

11. Search for the condition by entering a name into the Condition Name field and

then clicking Search. 12. In the Results table, select that condition.