> For the complete documentation index, see [llms.txt](https://docs.cloudeka.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.cloudeka.ai/guidance-for-enterprise/deka-gpu/deka-gpu-deka-guard/create-deka-guard/create-with-form.md).

# Create with Form

On the Deka Guard page, click the **+ Create Guard** button and select **Create with Form**.

<figure><img src="/files/KCLsdKaNesd2ZGZz8m6F" alt=""><figcaption></figcaption></figure>

The Create Guard page will be displayed. Complete the required fields, including **Name**, **Namespace**, and **Endpoint Selector**.

<figure><img src="/files/SPOPDokZR1E4SqpiTXaj" alt=""><figcaption></figcaption></figure>

The **Endpoint Selector** section is used to define the target pod for the rule by using a label selector. In this example, use **app=web-app** as the label selector, then click **Add**.

<figure><img src="/files/OB0DpWNkN49gNwwhOy5F" alt=""><figcaption></figcaption></figure>

Configure the global options for **Ingress Deny** or **Egress Deny**.

<figure><img src="/files/SI0BmuRlFX1rVCWbcehX" alt=""><figcaption></figcaption></figure>

When **Ingress Deny** is enabled, all incoming traffic to the selected endpoint is blocked. When **Egress Deny** is enabled, all outgoing traffic from the selected endpoint is blocked. To allow specific traffic, add a **CIDR** or **Selector** rule using the **New Rule** button under the Ingress Deny or Egress Deny section. This guide uses an example of adding a rule to **Ingress Deny**. Click **New Rule**.

<figure><img src="/files/TH95S2glr6hFbDHFXeQ0" alt=""><figcaption></figcaption></figure>

The **Create Ingress** window will be displayed. Select the desired **Type**.

<figure><img src="/files/TROGnR7VJdnSUZWcbrrX" alt=""><figcaption></figcaption></figure>

If **Selector** is selected, only the **Selector** and **Port** fields are displayed.

<figure><img src="/files/mZS8TpXnb0UX8eoFrG8K" alt=""><figcaption></figcaption></figure>

If **CIDR** is selected, the **Selector**, **Port**, and **Exception** fields are displayed. After completing the configuration, click **Add**.

<figure><img src="/files/XODbUgubozxEsLGviWqb" alt=""><figcaption></figcaption></figure>

Click **Submit** to create the Deka Guard.

<figure><img src="/files/QZCaNfVR8QwAZNVOLgpT" alt=""><figcaption></figcaption></figure>

A notification stating **"Guard has been successfully created."** will appear when the Deka Guard is successfully created in Service Portal Cloudeka.

<figure><img src="/files/OGqWJGsABTFe0DJCXkGc" alt=""><figcaption></figcaption></figure>
