Focus
Strata Cloud Manager

Configuration: Policy Optimizer

Table of Contents

Configuration: Policy Optimizer

Optimize overly permissive security rules including rules defined in Strata™ Cloud Manager snippets so that they only allow the applications and users that are actually in use in your network.
Where Can I Use This?What Do I Need?
  • NGFW, including those funded by Software NGFW Credits (Managed by Strata Cloud Manager and Panorama)
  • Prisma Access (Managed by Strata Cloud Manager and Panorama)
→ The features and capabilities available to you in Strata Cloud Manager depend on which license(s) you are using.
Rules that are too broad introduce security gaps because they allow traffic that is not in use in your network. Policy Optimizer converts overly permissive security rules into specific, focused rules that only allow the applications and users you actually have in your network. It analyzes traffic logs against your existing rules and autogenerates recommendations that enforce least-privilege access without disrupting business continuity.
Accepting a recommendation does not remove the original rule. The original rule remains in your Security policy, listed below the optimized rules, so you can monitor it and remove it when traffic hits reach zero. Policy Optimizer runs daily—you can see the timestamp of the last successful run at the top-right corner of the Policy Optimizer page. Both the original rule and the optimized rules are tagged so you can identify them easily in your Security policy.
You can customize the policy analysis lookback period between 15 and 90 days in Policy Optimizer Settings to align with your security posture requirements. You can optimize a rule again after the configured lookback period has elapsed—specifically, on the (n+1)th day after a lookback period of n days.
Policy Optimizer displays your rules across three tabs:
  • Ready for Optimization: Rules available for optimization.
  • Removed from Optimization: Rules excluded from optimization.
  • Optimization Failed: Rules with failed optimization attempts.

How Policy Optimizer Selects Rules

Before analyzing traffic and generating recommendations, Policy Optimizer evaluates each security rule against the following criteria.
Automatic selection: A rule is automatically selected when all of the following conditions are met:
  • The rule is enabled and has an allow action.
  • The rule has any specified in the source address, destination address, source user, or application fields.
  • The rule must have been analyzed over a configurable log retention period (by default 15 days, up to 90 days) and have valid traffic containing non-null zone, address, and application data.
Manual selection: You can add the predefined Enable-AIOps-Optimization tag to any rule to flag it for optimization, even if it was not automatically selected. This is useful when a rule's fields are still more permissive than necessary, or when zone fields are set to any and you want recommendations on those fields.

How Policy Optimizer Generates Recommendations

Once a rule qualifies, Policy Optimizer analyzes its associated traffic logs and maps observed data to your existing configuration objects. It then generates one or more tightly scoped replacement rules. The following sections describe how each field is processed.
Source and Destination Zones
Policy Optimizer analyzes logs for the exact zones traversed by matching traffic, and recommended rules restrict access exclusively to those zones. For Prisma® Access environments, zones are mapped to standard trust or untrust models. For snippet rules, zone fields are preserved as-is because snippets are zone-agnostic by design and must remain valid across all locations where the snippet is attached.
Source and Destination Addresses
Address optimization replaces broad any rules with strict IP and network boundary definitions based on observed flows:
  • Subnet up-leveling: Individual observed IP addresses are first consolidated into broader standard network subnets for a clean, manageable policy structure.
  • Mapping to configuration objects: Consolidated networks are matched against your predefined address objects (such as ip-netmask and ip-range) and address groups. If a defined address group accurately covers the traffic, the group is recommended instead of individual objects to keep the rulebase concise.
  • Standard IP ranges: Addresses that fall within RFC-1918 private subnets (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) or other special-use ranges are automatically recommended using standard subnets, even if no explicit address objects exist.
  • Public IP traffic: For rules with a large number of global public IP addresses, Policy Optimizer recommends all public IPs using negation of the three standard RFC-1918 private subnets, ensuring that traffic to internal infrastructure remains restricted.
Source User
User-to-application optimization enforces identity-based security per rule when your Strata Cloud Manager tenant is integrated with Cloud Identity Engine (CIE). Policy Optimizer matches each traffic flow to defined individual users and user groups, and recommends the most specific set that covers the observed traffic:
  • If the set of users exceeds the simplified tracking limit (10 by default), Policy Optimizer recommends the predefined keyword known-user, which enforces that only authenticated domain users have access and drops anonymous traffic.
  • If traffic logs contain no associated user data for unauthenticated endpoints, Policy Optimizer recommends the predefined keyword unknown, allowing you to build a specific rule for unauthenticated device access.
  • A minimum threshold of 75% is required to associate individual users with a user group—at least 75% of the user group's resolved user IDs must appear in the log data for the group to be recommended.
  • Policy Optimizer does not recommend additional users beyond those already permitted by the original rule. Recommendations only refine the rule to be more specific.
  • If CIE is unavailable, source user optimization is skipped and the original rule's Source User field is preserved unchanged.
Click Users in the recommendations panel to view the full list of users in a side panel. For recommendations where the source user is unknown, click Unknown User to open Log Viewer and review the associated traffic.
Applications
Replacing port-based rules with App-ID policies is central to the optimization. Policy Optimizer observes raw application signatures in traffic logs and builds granular application policies:
  • Observed applications are consolidated and recommended as defined application groups, application filters, or predefined Applipedia containers where applicable.
  • Policy Optimizer automatically detects and includes any underlying application dependencies required for the observed applications to function properly.
  • Traffic involving unknown applications (such as unknown-tcp or unknown-udp) is categorized separately, generating isolated rules so you can investigate unidentified traffic patterns.
Service
The service field is evaluated in relation to the detected applications:
  • If all detected applications used their standard protocol and ports, Policy Optimizer recommends setting the service field to application-default (if the original value was any). This ensures that applications cannot run on non-standard ports.
  • If applications ran over non-standard ports, Policy Optimizer retains the original service object configurations to prevent breaking legacy application flows.
Tags
Policy Optimizer automatically applies tags to help you identify original and optimized rules in your Security policy:
  • The original rule's name receives an _original suffix (for example, security-rule-name_original).
  • Each recommended optimized rule receives a tag with a _derived suffix (for example, security-rule-name_derived).
Clustering and Rule Formulation
In complex environments, a single overly permissive rule may serve multiple distinct functions. For example, allowing specific users to access IT applications and different users to access HR applications. Instead of replacing the original rule with one large, combined rule, Policy Optimizer clusters observed traffic into distinct groups based on IP networks and application categories. This produces multiple specific, easy-to-read rules that together cover all necessary business traffic while closing broad security loopholes. As a safeguard, a recommended optimized rule never allows traffic that was not already permitted by the original rule.

Policy Optimizer Support for Snippet Rules

In addition to rules defined directly in folder or device containers, Policy Optimizer evaluates rules defined within snippets. Policy Optimizer now treats snippet rules as first-class optimization targets. When you select Strata Cloud Manager as the device scope, snippet rules appear alongside folder and container rules in the optimization grids. The Location column displays the snippet name to identify where each rule is defined. A snippet is a reusable configuration object that you can associate with multiple folders, devices, or deployments simultaneously. When you associate a snippet with a container location, Strata™ Cloud Manager applies its rules to all traffic handled by that location. Optimizing snippet rules ensures that security improvements apply consistently across every associated deployment.
You can manage recommendations for snippet rules using standard Policy Optimizer actions:
  • Accept: Saves the optimized rules back to the snippet. Changes propagate automatically to every location where the snippet is attached.
  • Merge: Combines related rules within the snippet to streamline your rulebase.
  • Disable: Deactivates unused or redundant snippet rules across all associated containers.
  • Revert: Restores original snippet rule settings when necessary.
Snippets are designed to be zone-agnostic so that their rules function correctly across locations with varying zone topologies. To maintain multi-location compatibility, Policy Optimizer preserves source and destination zone fields as any when generating recommendations for snippet rules.
Policy Optimizer narrows all other rule fields based on observed traffic, including:
  • Applications
  • Source IP addresses
  • Destination IP addresses
  • Source users
This selective narrowing produces recommendations you can apply once to the snippet and have take effect correctly across all associated deployments. Snippet rule optimization applies exclusively to Strata Cloud Manager.

Policy Optimizer for Panorama-Managed Configurations

Policy Optimizer supports Panorama-managed configurations alongside Strata Cloud Manager managed devices within the same tenant. Strata Cloud Manager maintains separate optimization workflows for each management type while providing a unified interface for viewing and managing recommendations across your entire firewall deployment.
Policy Optimizer considers both Cloud Identity Engine data and locally defined users within Panorama templates when generating user-based optimization recommendations, and maintains separate recommendation sets for applications with known App-IDs and those where the App-ID is unknown.
For Panorama-managed configurations, accepting recommendations requires pushing changes to the candidate database in Panorama rather than applying them directly to individual firewalls. You must then commit those changes in Panorama. Policy Optimizer provides status tracking for remediation operations, including pending, success, and error states.
To use Policy Optimizer for Panorama-managed configurations, complete the following prerequisites:
  • Onboard your Panorama device to Strata Cloud Manager and associate it with a Tenant Service Group (TSG).
  • Enable Strata Logging Service on Panorama. Ensure the correct region and product usage configuration is set to provide the necessary traffic data for optimization recommendations.
  • Install and enable Panorama CloudConnector Plugin 3.0.0 or later.
  • Sync the configurations with Strata Cloud Manager for the CloudConnector plugin to detect and process the updated configuration:
    > request plugins cloudconnector sync enable
  • Commit your configuration changes in Panorama and validate that the commit is successful to initiate analysis by Policy Optimizer.
    If you encounter issues with Policy Optimizer for Panorama configurations, commit your changes again and verify that the commit is successful. Collect the TSF file and send it to Palo Alto Networks support for further investigation.

Guidelines and Limitations for Policy Optimizer

  • Address Group Creation:
    • Supported only when recommendations contain IP addresses.
    • Not supported if recommendations include a combination of IP addresses and existing address or address group objects, existing address objects only, or both IPv4 and IPv6 addresses.
    • The checkbox for creating address groups in the side panel is not selected by default for rules in the global scope.
    • A validation error does not appear if the address group name is a duplicate or if an address object with the same name already exists.
  • You can optimize a rule again after the configured lookback period has elapsed. If the lookback period is set to n days, reoptimization is available on the (n+1)th day.

Optimize a Rule

To optimize rules for Panorama-managed deployments, first complete the prerequisites in Policy Optimizer for Panorama-Managed Configurations. The following steps apply to deployments managed by either Strata Cloud Manager or Panorama.
  1. Select ConfigurationPosturePolicy Optimizer.
  2. At the top of the page, select Cloud Manager for Strata Cloud Manager-managed deployments, or a Panorama instance for Panorama-managed deployments.
    The Ready for Optimization tab lists all overly permissive rules with available recommendations, sorted by traffic volume with the highest-hit rules first. When you select Strata Cloud Manager, snippet rules appear alongside folder rules; the Location column shows the snippet name for snippet rules and a folder or container name for all others.
    For Panorama-managed rules, the Location field shows the specific device group. The Modified and Creation dates are empty for Panorama rules.
    If no rules have been optimized by Policy Optimizer, a banner appears to indicate this.
  3. Select a rule to view its optimization recommendations.
    You can see how much of the original rule's traffic each new rule covers and review the specific applications each rule enforces. View recommendations by Overall Traffic, Session Count, or Number of Unique Users. All recommended rules are prepended with optrule and appended with an integer.
  4. Adjust the recommended rules before accepting.
    • Edit the name of any optimized rule.
    • Delete individual applications or application groups in the Applications sidecar.
    • Disable a recommended rule to exclude it from acceptance. The rule is removed from the recommendation list and is not added to the rulebase.
    • Revert to undo all local edits and restore the original recommendations. You can revert disabled rules as long as they have not been accepted yet.
    • Merge two or more similar recommended rules into a single rule. Negated and unnegated addresses cannot be merged.
    • Create source or destination address groups within recommendations to manage policies at scale. The address group retains the original configuration scope by default. Enable the checkbox to change it to the global scope.
  5. Accept some or all recommendations.
    Click Accept All to accept all recommended rules as-is, or select individual rules to accept.
    • For Strata Cloud Manager-managed configurations: After accepting, click Update Rulebase. The optimized rules are added to your Security policy but do not enforce traffic yet. For snippet rules, Strata Cloud Manager saves the optimized rules back to the snippet directly, and the change propagates to all associated locations automatically. Click Push Config to start enforcing the optimized rules.
    • For Panorama-managed configurations: After accepting, the Optimization Summary window appears. Click Update Panorama Rulebase to push the configurations to the Panorama candidate config. Then log in to Panorama and commit the changes. See Preview, Validate, or Commit Configuration Changes.
    The Optimization History tab shows statuses for Panorama-managed rules:
    • Updated in Candidate Config—Pending commit.
    • Success—Updated in Candidate Configuration.
    • Error—The rule is automatically returned to the optimization queue. A tooltip provides the specific error message.
    After optimizing a security rule, Policy Optimizer does not reselect it for further optimization for the next 15 days. This prevents redundant recommendations on the same traffic after other optimized rules have been applied.
  6. Monitor the original rule until you are confident you no longer need it.
    The original rule remains in your Security policy below the optimized rules, tagged with _original appended to its name (for example, security-rule-name_original). Each recommended rule carries a _derived tag for easy identification.

Remove a Rule from Optimization

Move a rule to the Removed from Optimization list, and Policy Optimizer does not optimize it. The rule settings remain as-is.
Make sure to Push Config after moving a rule to the exclusion list. After pushing the configuration, it can take up to 24 hours for the rule to display on the list. You can always add the rule back to the optimization list later.
Under Optimization Failed, you can view the rules that failed optimization and check the reason for failure.

Track Optimization Results

Policy Optimizer shows a history of the security rules you have optimized. Historical data includes the optimization results: compare the original rule's traffic coverage against the optimized rules. You can also view how many days have passed since you accepted a rule for optimization.
If an original rule gets no hits, Policy Optimizer removes it from the optimization history and classifies it as a zero-hit policy rule instead.