Policy simulation
Preview an access decision before changing a grant.
Use Policy Simulation to test how current access policy would evaluate a user, device, service, and gateway context.
Run a simulation#
- Open Network → Access and choose Simulate, or open Policy Simulation from the command palette.
- Select the subject and device.
- Select the destination service and gateway context.
- Run the simulation and inspect the matched policy chain, priorities, and final decision.
- Follow links to edit the relevant policy, then simulate again.
Interpret the result#
Lower priority numbers evaluate earlier. A simulation helps expose overlapping Allow and Deny rules, missing services, and scope mistakes. It is a preview based on the supplied context and current configuration, not proof that a live tunnel, gateway, posture report, or firewall path is healthy.
For L3/L4 rule testing, use the simulator inside a Firewall rule. That tool checks one rule only and does not model the complete ruleset or end-to-end access.