Hello, I have a policy for user group (LOCAL-NET wich already include server BACKUP-SERVER ) to Internet with application feautures skyatp, idp, utm.
I need exclude 1 address from this policy, but i need that this address (BACKUP-SERVER 192.168.20.20/32) still have internet from other policy without application feautures
set security zones security-zone trust address-book address DATA-NET 192.168.200.0/24set security zones security-zone trust address-book address DATA-CLOUD1 192.168.20.0/24set security zones security-zone trust address-book address DATA-CLOUD2 192.168.23.0/24set security zones security-zone trust address-book address BACKUP-SERVER 192.168.20.20/32set security zones security-zone trust address-book address-set LOCAL-NET address DATA-NETset security zones security-zone trust address-book address-set LOCAL-NET address DATA-CLOUD1set security zones security-zone trust address-book address-set LOCAL-NET address DATA-CLOUD2set security policies from-zone trust to-zone untrust policy USERS-to-INET-POLICY match source-address LOCAL-NETset security policies from-zone trust to-zone untrust policy USERS-to-INET-POLICY match destination-address anyset security policies from-zone trust to-zone untrust policy USERS-to-INET-POLICY match application anyset security policies from-zone trust to-zone untrust policy USERS-to-INET-POLICY then permit application-services idp-policy COPY-CLIENT-SERVER-POLICY-IDPset security policies from-zone trust to-zone untrust policy USERS-to-INET-POLICY then permit application-services utm-policy test-utmset security policies from-zone trust to-zone untrust policy USERS-to-INET-POLICY then permit application-services security-intelligence-policy secintel_policyset security policies from-zone trust to-zone untrust policy USERS-to-INET-POLICY then permit application-services advanced-anti-malware-policy aamw-policyset security policies from-zone trust to-zone untrust policy USERS-to-INET-POLICY then countset security policies from-zone trust to-zone untrust policy BACKUP-SERVER-to-INET-POLICY match source-address BACKUP-SERVERset security policies from-zone trust to-zone untrust policy BACKUP-SERVER-to-INET-POLICY match destination-address anyset security policies from-zone trust to-zone untrust policy BACKUP-SERVER-to-INET-POLICY match application anyset security policies from-zone trust to-zone untrust policy BACKUP-SERVER-to-INET-POLICY then permit