Configure Rule Targeting
Focus
Focus
Network Security

Configure Rule Targeting

Table of Contents

Configure Rule Targeting

Rule targeting lets you specify which NGFWs receive a given policy rule at push time, so you control precisely where each rule takes effect across your fleet.
Where Can I Use This?What Do I Need?
  • NGFW (Managed by Strata Cloud Manager)
  • One of the following licenses:
  • A role with permission to edit security policy
  • NGFWs managed at the container scope level in Strata Cloud Manager
When you manage multiple NGFWs in Strata Cloud Manager, policy rules defined at the container scope are pushed to all devices in that scope by default. Rule targeting lets you restrict a rule so that Strata Cloud Manager pushes it only to a specific set of NGFWs, rather than every device in the container. This is the Strata Cloud Manager equivalent of the rule-targeting capability available in Panorama.
You configure targeting by specifying an enabled-devices list on the rule. The list contains the serial numbers of the NGFWs that should receive the rule. When Strata Cloud Manager pushes configuration, it delivers the rule only to the NGFWs you named and skips all others in the scope. Because targeted rules apply to a subset of devices, you must disable the rule before adding targets—enabled rules apply to all devices in the scope and cannot be targeted.
Rule targeting also preserves your existing Panorama configuration when you migrate to Strata Cloud Manager. If a Panorama device group contains rules with <target> nodes, the migration service converts those targeting settings to the enabled-devices format and marks the rules as disabled so they are ready for you to review and re-enable. Rules that target specific virtual systems or device tags in Panorama are not migrated with targeting intact because multi-vsys targeting is not supported in Strata Cloud Manager. Currently, rule targeting is supported only for security rules configured in folders.
  1. Select ConfigurationNGFW and Prisma AccessSecurity ServicesSecurity Policy, or navigate to the applicable policy type.
  2. Select the Configuration Scope (folder) where the rule is defined.
    Rule targeting is available only for rules defined at the container scope level.
  3. Select the rule you want to target, or click Add Rule to create a new one.
    See Security Policy Rules for more information about creating and defining rules.
  4. Disable the rule if it is not already disabled.
    Rule targeting requires the rule to be in a disabled state. You cannot add target devices to an enabled rule.
  5. Select Target.
  6. Add and enter the serial number of each NGFW to which you want to apply the rule.
    The device name auto-complete returns NGFWs that are descendants of the container scope where the rule is defined. If you do not add any target devices, the rule applies to all NGFWs in the scope when you re-enable it.
  7. Save.
  8. Push the configuration to deliver the rule to the targeted NGFWs.
    Strata Cloud Manager delivers the rule only to the NGFWs listed in the target. All other NGFWs in the scope do not receive this rule during the push.
    1. Push Config.
    2. In the push scope, select the container that contains the targeted rule.
    3. Push.