Optimize overly permissive security rules so that they only allow applications that
are actually in use in your network.
| Where Can I Use
This? | What Do I Need? |
|
| → The features and capabilities available to you in Strata Cloud Manager depend on which license(s) you are
using. |
Rules that are too broad introduce security gaps because they allow traffic
that isn't in use in your network. Policy Optimizer enables you to convert these
overly permissive rules to more specific, focused rules that only allow the
applications you’re actually using.
Strata Cloud Manager analyzes log data and flags rules as overly permissive
if they are at least 15 days old and have "any" specified in the source address,
destination address, or application fields.
For rules identified as overly permissive, Strata Cloud Manager
autogenerates recommendations you can accept to optimize the rule. The new,
recommended rules are more specific and targeted than the original rule; they
explicitly allow only the applications that have been detected in your network in
the last 15 days.
Select an overly permissive rule to review, adjust, and accept optimization
recommendations. Replacing these rules with the more specific, recommended rules
strengthens your security posture.
Accepting recommendations to optimize a rule does not remove the original rule. The
original rule remains listed below the new rules in your Security policy so you can
monitor the rule and remove it when there is zero traffic hit on the original rule.
Policy Optimizer process runs daily and you can see the timestamp of the last
successful process run at the top-right corner of the Policy Optimizer page. Both
the original rule and optimized rules are tagged so you can easily identify them in
your Security policy.
Policy Optimizer analyzes rules that are at least 15 days old for
optimization. You can customize the policy analysis lookback period between 15 and
90 days in the Policy Optimizer settings to align with your security posture
requirements. To adjust the lookback period, go to Policy Optimizer, open the
Policy Optimizer Settings at the top right corner of the page, and enter
a value between the default 15 days and the maximum 90 days.
You can optimize a rule again after the configured lookback period has elapsed.
Specifically, if the lookback period is set to 'n' days, reoptimization becomes an
option on the (n+1)th day. For example, a 15-day lookback period allows for rule
reoptimization on the 16th day.
You can view the below information in Policy Optimizer:
Ready for Optimization: Rules available for
optimization.
Removed from Optimization: Rules excluded from
optimization.
Optimization Failed: Rules with failed optimization attempts.