Hello, It is possible to have subject in policy with enabled learning mode for it and this subject will unable to use network completely (bind and connect disabled)? Thanks.
It's not possible within RBAC to partially restrict a subject under learning. There exist netfilter modules to deny traffic in/out of specific processes though.
Ok. And similar question: there is role with enabled learning. Will existing subjects for that role (specified after role definition) still work, or they will be ignored? Thanks.