Skip to content →
Log in

Policy simulation

Preview an access decision before changing a grant.

Use Policy Simulation to test how current access policy would evaluate a user, device, service, and gateway context.

Run a simulation#

  1. Open Network → Access and choose Simulate, or open Policy Simulation from the command palette.
  2. Select the subject and device.
  3. Select the destination service and gateway context.
  4. Run the simulation and inspect the matched policy chain, priorities, and final decision.
  5. Follow links to edit the relevant policy, then simulate again.

Interpret the result#

Lower priority numbers evaluate earlier. A simulation helps expose overlapping Allow and Deny rules, missing services, and scope mistakes. It is a preview based on the supplied context and current configuration, not proof that a live tunnel, gateway, posture report, or firewall path is healthy.

For L3/L4 rule testing, use the simulator inside a Firewall rule. That tool checks one rule only and does not model the complete ruleset or end-to-end access.