About policy change impact insights
Changes to an access control policy can affect network traffic in unexpected ways. A modification that appears minor, such as updating a network object, expanding a rule, or changing rule conditions, can alter how traffic is evaluated by other rules in the policy. These effects are often difficult to identify before deployment.
Policy Change Impact Analyzer helps you review the potential impact of pending access control policy rule changes across devices before deployment. The analysis helps you identify affected rules, impacted connections, and traffic segments so that you can better understand the consequences of a change before deploying it. The Policy Change Impact Analyzer evaluates proposed policy changes and provides visibility into:
-
The overall analysis result for each device
-
Affected devices and rules
-
Impacted traffic segments
-
Historical connections affected by a changed rule, when traffic data is available
-
Rule-level inferred impact
-
AI-generated summaries that explain the potential effect of a rule change
Limitations and considerations
-
Currently, Policy Change Impact Analyzer supports Cloud-Delivered Firewall Management Center-managed Firewall Threat Defense devices only.
-
Policy Change Impact Analyzer is available only for deployments in the US, AUS and EU regions.
-
High Availability and cluster deployments are represented by their parent target during analysis.
-
Impacted connection counts are available only when Security Analytics and Logging is enabled and connection events are sent for FTD Management Services.
-
Running an analysis does not deploy, edit, approve, or reject policy changes.
-
AI-generated explanations support decision-making. Validate important findings against your security requirements and operational policies before deployment.
-
Review analysis results before approving production changes, especially high-risk policy modifications.
Understand analysis results
Review the assessment result to understand the likely effect of pending policy changes and the recommended next steps.
Note | An analysis result does not indicate whether a change is approved. Review the transition direction, affected rule, and traffic conditions before deployment. |
|
Analysis result |
What it means |
Recommended action |
|---|---|---|
|
Critical |
One or more changes may expose the network to threats or disrupt services. |
|
|
Potential impact |
One or more changes expand access or may affect traffic. |
Validate the affected traffic and the expected business outcome before deploying. |
|
Improved security posture |
One or more changes reduce exposure or block risky traffic. |
Confirm that the affected traffic is intentionally restricted, then continue through normal change review. |
|
No traffic impact |
No behavior-changing traffic transition was identified from the policy comparison. |
|
|
Indeterminate |
The available evidence was insufficient to determine a reliable impact. |
|
Understand job statuses
Job Status shows the current state of the policy impact analysis and whether the latest result is available and up to date.
|
Job status |
Description |
|---|---|
|
Verifying analysis is up to date |
The system is checking whether the latest analysis still matches the pending policy changes. |
|
Queued |
The analysis request was accepted and is waiting to run. Wait for the status to change to In progress. |
|
Completed |
The latest analysis completed successfully. A warning icon may appear if a policy analysis returned an error. |
|
Partial success |
Useful assessment results are available, but one or more stages did not complete. Review the available details and Workflows before deciding whether to rerun. |
|
In progress |
The system is preparing policy data, calculating impact, or collecting connection evidence. Wait for the result or open Workflows to monitor progress. |
|
Out of date |
The policy changed after the analysis started, or the analysis is more than 24 hours old and its traffic evidence may no longer be current. Rerun the analysis to get the latest results. |
|
Failed |
The latest overall analysis failed. Review the error and Workflows details, then rerun the analysis if appropriate. |
|
Cancelled |
The analysis was cancelled by an authorized user before completion. |
|
Not analyzed |
No analysis is available for the device, or the device has pending changes that have not yet been analyzed. Select a device and run the analysis. |
|
Not applicable |
No pending policy changes are available for analysis. Create or save the intended policy changes, then run the analysis. |
|
Unknown |
The system could not determine a reliable current status. Refresh the device list and try again later. If the issue persists, review the workflow details. |
Understand inferred impact
Inferred Impact describes the likely effect of an individual changed rule or affected rule.
|
Inferred impact |
Description |
|---|---|
|
Potential threat exposure risk |
The change may allow risky applications, risky URL categories, broad application or URL scope, sensitive destination ports, or broad Internet exposure. |
|
Potential service disruption |
The change may block sensitive services or high-volume business traffic. |
|
Access expansion |
The change may allow traffic that was previously blocked without a clear risky-application or sensitive-port signal. |
|
Indeterminate |
The available evidence was insufficient, or the impact assessment did not complete. |
|
Improved security |
The change blocks risky or untrusted traffic, or reduces broad external exposure. |
|
No traffic impact |
No behavior-changing traffic transition was detected. |
Impacted traffic segments and connections
An Impacted Traffic Segment is a distinct combination of traffic conditions whose policy outcome, such as allow or block, changes when the proposed policy changes are deployed.
-
Traffic conditions may include source and destination zones, networks, applications, URLs, users, services, ports, security-group tags, and geolocation identities.
-
The number of impacted traffic segments is not the number of rules, packets, IP addresses, or historical connections.
Impacted Connections shows the number of historical connections associated with traffic affected by a changed rule.
-
The count is based on available Security Analytics and Logging connection-event data. It represents observed historical activity, not a forecast of future traffic.
-
If connection events are unavailable, the analyzer can still identify impacted traffic segments, but historical connection counts are not available.
-
Review the policy comparison and traffic segments instead of treating unavailable data as zero traffic.
Understand policy analysis limitations
Some policy constructs are not fully evaluated during analysis. Review affected rules manually before deployment when these constructs are involved.
-
Object overrides are not considered during analysis. For example, if a port object has the value
8080but is overridden to80for a particular device, the device-specific value80is not considered. -
Country, continent, and custom geolocation objects are expanded to country-level identities. They are not expanded to IP-level identities, and individual IP addresses are not compared.
-
URL category reputation is not considered. For example, if a new rule uses the same URL category with a different reputation, the analyzer may report No Traffic Impact even though the reputation changed.
-
URL list and URL feed objects are not expanded into individual URLs. The analyzer reports an impact only when the object is used in an affected traffic fragment or segment. Individual entries in the list or feed are not evaluated separately.
-
Time-range support is limited. Only active time ranges are considered. Rules with future or expired time ranges are treated as disabled. Changes to the time-range configuration itself are not considered during analysis.
-
Dynamic-attribute support is limited to Security Group Tags (SGTs), including supported FMC and ISE SGT references. CSDAC-backed dynamic attributes and other unsupported dynamic-object criteria are not analyzed.
-
Application filters entered directly in the application field, such as Very High or High risk or business relevance criteria, are not supported when they are inline filters rather than user-defined application filter objects. User-defined application filters, including filters that combine multiple criteria, are supported.