Identify Rules to Improve

Determine the Security policy rules you need to tighten to improve security using using the Best Practice Assessment tool.
After you identify a gap in security policy capability adoption, use the
Rule Detail
view to list rules that require further investigation or remediation. Configure
Column Filters
to match the gap identification criteria you developed when you identified gaps in adoption. This results in rule lists you can export and hand off to the operational team in charge of firewall Security policy.
For example, to create a Rule Detail filter to identify rules that allow all traffic and don’t have a Vulnerability Protection profile configured:
  1. In the Heatmaps section of the BPA, click
    Rule Detail
    .
  2. Click
    Column Filters
    to expand the filter options and then select the following filters:
    • Source Zone =
      any
    • Destination Zone =
      any
    • Source Address Configured =
      No
    • Destination Address Configured =
      No
    • Action =
      allow
    • Rule Enabled =
      Yes
    • Vulnerability On =
      No
    rule-detail-column-filters-selected.png
  3. Click
    Apply Filters
    .
    The BPA lists the rules that match the filters:
    rule-details-filter-config.png
  4. To export the filtered rule list to a .csv file, click
    Export Data
    .
    rule-details-export-to-csv.png

Recommended For You