Optimize a high expansion rule

Reduce the rule contribution to the Access Control Entry count before deployment.

  1. Open the rule that shows a rule-level warning or appears in the high expansion rule list.

  2. Apply the high expansion rules filter again to confirm that the rule no longer drives excessive expansion.

  3. Review source networks, destination networks, source ports, destination ports, virtual LAN tags, source security zones, destination security zones, inline values, objects, and nested object groups.

  4. Remove unnecessary objects or inline values, reduce overly broad nested object groups, or adjust optimization settings when the change matches the policy intent.

  5. Remove overlapping rules.

  6. Save the rule.

Deploy Policy Analyzer and Optimizer

If the high expansion rules filter does not help reduce the number of access control entries (ACE), use the Policy Analyzer and Optimizer feature to detect common design anomalies, including duplicate rules, overlapping objects, expired rules, and mergeable rules.

As a cloud-delivered feature, Policy Analyzer and Optimizer is available in Security Cloud Control. You can access the feature directly in Security Cloud Control or by using a cross-launch from Firewall Management Center.

To learn more, refer to Policy Analyzer and Optimizer.