Policy Analyzer and Optimizer
Policy Analyzer and Optimizer is an intelligent Security Cloud Control Firewall Management service that
-
analyzes firewall policies and detects rule anomalies
-
helps you understand where a policy can be optimized, and
-
supports access control policies policies for Cloud-Delivered Firewall Management Center and supported Security Cloud Control-managed On-Premises Firewall Management Center data sources.
Capabilities and benefits
AgenticOps for firewalls provides operational insights and tools that help improve firewall management, policy hygiene, and deployment readiness. One such capability is Policy Analyzer and Optimizer, which uses an algorithmic approach to evaluate firewall policy rules and identify anomalies such as duplicate, shadowed, redundant, or otherwise optimizable rules. For more information, refer to AgenticOpsInsights to know more about the various other functionalities that AgenticOps provides.
Secure Firewall Threat Defense devices with extensive policies may have numerous duplicate or shadowed rules. Such large policies with unoptimized rulesets can lead to excessive consumption of device memory, delayed loading of rules, and long search duration, resulting in inefficient security policy enforcement, reduced network speeds, and extended deployment durations.
Policy Analyzer and Optimizer can perform these functions:
-
View policy health and optimization opportunities for the selected management center data source.
-
Analyze policies on demand or rely on scheduled analysis that runs every 24 hours.
-
Download analysis reports as PDFs after analysis completes.
-
Use Access Control Policy Analyzer and Optimizer remediation workflows where supported.
-
Stage and apply remediation for an entire anomaly category, selected observations, or individual rules within supported observations.
-
Use Network Address Translation Policy Analyzer and Optimizer findings and AgenticOps insights to investigate NAT policies that contain optimizable rules.
Security Cloud Control Firewall Management performs anomaly analysis on these policy types:
|
Policy type |
Use this section when |
Current scope |
|---|---|---|
|
Access control policy |
You want to analyze access control policies, review access control findings, and apply supported remediations. |
Analysis, remediation, reporting, remediation history, and policy insights. |
|
Network address translation policy |
You want to analyze NAT policies for shadowed and redundant NAT rules. |
Analysis and reporting for fully shadowed and fully redundant NAT rules. NAT remediation is not available in this release. |