Configure Nested Functions for Complex Rules
The Nested Functions feature provides the flexibility to create complex filtering rules by chaining multiple criteria within a single criteria parameter. This functionality enables the construction of criteria entities to define sophisticated policies.
Do the following to define or modify a ruleset using nested parameters:
- In Secure Web Gateway Cloud, go to Policy > Web Policy > Policy.
- On the Web Policy tree, select criterion Request Header.

- Click Add Parameter to open the configuration side panel.
- in the Header Name configuration area, define the parameter type:
- Value. Enter a standard string or numerical value as a parameter.
- Function. Select from a list of available criteria that can be nested.
- Build or modify the nested chain:
- Add Criteria Function. Selecting a function adds a new node to the criteria entity on the left side of the interface. Continue adding functions to these nodes to extend the chain to any required depth.
- Update existing nodes. Click on a specific node in the tree to view or modify its existing configurations on the right side.
- Configure and save the nested chain:
- Select each node in the tree to enter its specific values on the right side.
- In the Name Your Configuration field, provide a unique identifier for the configuration.
- In the Description field, enter a brief explanation of the value’s purpose.
- Click Save to finalize the nested parameter chain.The completed chain appears as a single string within the rule.
- In the left-side nested tree of criteria side panel , click any existing node to view its configuration. The previously configured parameters populate in the right-side panel.
- Modify the details or parameters within the right-side panel as needed, then click Save.
- To extend the nested chain further from the selected node:
- In the right-side panel, select an alternative criteria from the Function drop-down list.A new sub-node is automatically appended to the nested structure.
- Configure the parameters required for the new function.
- Click Save to update the custom configuration and view the extended parameter chain.
- Select a condition, such as True or False, to define the final logic for the rule.
- Click Save.
- Click Publish to publish the changes.
