Local Configuration Management for NGFWs
Focus
Focus
Next-Generation Firewall

Local Configuration Management for NGFWs

Table of Contents

Local Configuration Management for NGFWs

Enhances readability, simplifies troubleshooting, and reduces manual effort by providing visibility and control over local firewall configurations through Strata Cloud Manager.
Where Can I Use This?What Do I Need?
  • NGFWs (Managed by Strata Cloud Manager)
One of these licenses:
  • Strata Cloud Manager Essentials
  • Strata Cloud Manager Pro
This feature is available on request. Contact your account team to enable the feature.
This feature is available on request. Contact your account team to enable the feature.
Managing local configurations directly in Strata Cloud Manager removes the need to constantly switch context between central management to individual NGFWs for managing. This feature enhances readability, simplifies troubleshooting, and reduces manual effort by providing visibility and control over local NGFWs configurations through Strata Cloud Manager. Additionally, it identifies any conflicting or overridden objects between local and pushed configurations, making it easier to troubleshoot.
  1. Log in to Strata Cloud Manager.
  2. Select ConfigurationNGFW and Prisma AccessOverview and expand the Configuration Scope and select a specific firewall from your Folders.
  3. You cannot configure policies and objects in device scope by default. To configure them, enable Device Scope Configuration.
  4. To view and resolve local configuration conflicts on NGFWs, select a folder or specific NGFW from your Folders on the ConfigurationNGFW and Prisma AccessOverview page.
    • Firewalls with config conflicts shows the number of firewalls with conflicts. View Conflicts to see conflicts for all firewalls and their respective locations. Click the individual firewall to further investigate device-level conflicts.
    • Objects with config conflicts shows the number of conflicts per firewall. Click the number to view the conflicted objects and their corresponding types specific to that firewall. Click the object to get the granular details on the conflict.
    • Select objects such as zones and interfaces to view any conflicts with the local device configuration.
    • Use the Show Config Diff option to compare configurations between the Strata Cloud Manager and the firewall.
  5. To maintain consistent configurations across multiple NGFWs and to improve operational efficiency, you can convert local configurations into centrally managed snippets. These snippets are then imported into Strata Cloud Manager as central policy objects.