Manage Device-ID
Focus
Focus

Manage Device-ID

Table of Contents

Manage Device-ID

Ensure your policy rule recommendations and device objects are current and delete imported rules when they're no longer needed.
Perform the following tasks as needed to ensure your policy rule recommendations and device objects are current.
  1. Update your policy rule recommendations as necessary.
    As IoT devices gain new capabilities, IoT Security updates its policy rule recommendations to advise what additional traffic or protocols firewalls should allow. Periodically check policy rule recommendations for profiles with recommendations you've previously imported (
    Device
    or
    Panorama
    Policy Recommendation
    IoT
    ). If there are additional ones without an entry in the Imported To column, they haven't been imported to the rulebase yet. Assess your security needs and consider importing these recommendations to the Security policy rulebase as described in Configure Device-ID.
  2. Review, update, and maintain the device objects in the Device Dictionary.
    You must create device objects for any devices that do not have an IoT Security policy rule recommendation. For example, you cannot secure traditional IT devices such as laptops and smartphones using IoT Security policy rule recommendations, so you must create device objects for these types of devices and use them in your Security policy rules to secure these devices.
    1. Select
      Objects
      Devices
      .
    2. Add
      a device object.
    3. Browse
      the list or
      Search
      using keywords.
      The search results can include multiple types of device object attributes (for example, both
      Category
      and
      Profile
      ).
    4. To add a custom device object, enter a
      Name
      and optionally a
      Description
      for the device object.
      Always use a unique name for each device object. Do not change the tags in the description for device objects from policy rule recommendations.
    5. (
      Panorama only
      ) Select the
      Shared
      option to make this device object available to other device groups.
    6. Select the attributes for the device object (
      Category
      ,
      OS
      ,
      Profile
      ,
      Osfamily
      ,
      Model
      , and
      Vendor
      ).
    7. Click
      OK
      to confirm your changes.
  3. Delete any policy rule recommendations that are no longer needed.
    If imported policy rules are no longer needed, you can remove them from the rulebase.
    1. Select
      Policies
      Security
      . For Panorama, select
      Policies
      Security
      Pre-Rules/Post-Rules
      .
    2. Select the rules you want to remove from the rulebase and then
      Delete
      them.
    3. Commit
      your changes.
      When you look at policy rule recommendations after deleting their corresponding rules from the rulebase, note that the Imported To column is now empty for them.
  4. Use CLI commands to troubleshoot any issues between the firewall and IoT Security.

Recommended For You