About Policy Analyzer and Optimizer
Secure Firewall Threat Defense devices with extensive access control policies, especially those generated through the firewall migration process, may have numerous duplicate or shadowed rules. Such bloated policies with unoptimized rulesets can lead to excessive consumption of device memory, delayed loading of rules, long search times, resulting in inefficient security policy enforcement, reduced network speeds, and extended deployment durations.
To deal with such situations, Security Cloud Control provides Policy Analyzer and Optimizer. It is an intelligent cloud service that can analyze security policies, detect anomalies, and provide recommendations on remediations that can be performed to optimize the policies, thereby improving the firewall performance. The Policy Analyzer and Optimizer can analyze policies both in the cloud-delivered Firewall Management Center and On-Premises Firewall Management Centers that are onboarded to Security Cloud Control. In addition, this feature can:
-
provide comprehensive visualization of policy health information, including an analysis overview and policy insights based on aggregate hit counts.
-
analyze policies regularly on scheduled intervals or whenever preferred.
-
detect rule anomalies, such as duplicate rules, object overlap in rules, and expired rules.
Note that the Policy Analyzer and Optimizer can get launched from Security Cloud Control's Services page, on the left pane, and on-premises management center's Access Control policies page for the administrator's convenience.