Rule targeting lets you specify which NGFWs receive a given policy rule at push time,
so you control precisely where each rule takes effect across your fleet.
| Where Can I Use This? | What Do I Need? |
When you manage multiple NGFWs in
Strata Cloud Manager, policy rules defined at the
container scope are pushed to all devices in that scope by default. Rule targeting
lets you restrict a rule so that
Strata Cloud Manager pushes it only to a specific
set of NGFWs, rather than every device in the container. This is the
Strata Cloud Manager equivalent of the
rule-targeting capability available in
Panorama.
You configure targeting by specifying an enabled-devices list on the rule.
The list contains the serial numbers of the NGFWs that should receive the rule. When
Strata Cloud Manager pushes configuration, it delivers the rule only to the
NGFWs you named and skips all others in the scope. Because targeted rules apply to a
subset of devices, you must disable the rule before adding targets—enabled rules
apply to all devices in the scope and cannot be targeted.
Rule targeting also preserves your existing Panorama configuration when you migrate
to Strata Cloud Manager. If a Panorama device group contains rules with
<target> nodes, the migration service converts those
targeting settings to the enabled-devices format and marks the rules as
disabled so they are ready for you to review and re-enable. Rules that target
specific virtual systems or device tags in Panorama are not migrated with targeting
intact because multi-vsys targeting is not supported in Strata Cloud Manager.
Currently, rule targeting is supported only for security rules configured in
folders.