Once a rule qualifies, Policy Optimizer analyzes its associated traffic logs and
maps observed data to your existing configuration objects. It then generates one
or more tightly scoped replacement rules. The following sections describe how
each field is processed.
Source and Destination Zones
Policy Optimizer analyzes logs for the exact zones traversed by matching traffic,
and recommended rules restrict access exclusively to those zones. For Prisma®
Access environments, zones are mapped to standard trust or untrust models. For
snippet rules, zone fields are preserved as-is because snippets are
zone-agnostic by design and must remain valid across all locations where the
snippet is attached.
Source and Destination Addresses
Address optimization replaces broad any rules with strict IP and network
boundary definitions based on observed flows:
Subnet up-leveling: Individual observed IP addresses are first
consolidated into broader standard network subnets for a clean,
manageable policy structure.
Mapping to configuration objects: Consolidated networks are
matched against your predefined address objects (such as ip-netmask and
ip-range) and address groups. If a defined address group accurately
covers the traffic, the group is recommended instead of individual
objects to keep the rulebase concise.
Standard IP ranges: Addresses that fall within RFC-1918 private
subnets (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) or other special-use
ranges are automatically recommended using standard subnets, even if no
explicit address objects exist.
Public IP traffic: For rules with a large number of global public
IP addresses, Policy Optimizer recommends all public IPs using negation
of the three standard RFC-1918 private subnets, ensuring that traffic to
internal infrastructure remains restricted.
Source User
User-to-application optimization enforces identity-based security per rule when
your Strata Cloud Manager tenant is integrated with
Cloud Identity Engine (CIE). Policy
Optimizer matches each traffic flow to defined individual users and user groups,
and recommends the most specific set that covers the observed traffic:
If the set of users exceeds the simplified tracking limit (10 by
default), Policy Optimizer recommends the predefined keyword known-user,
which enforces that only authenticated domain users have access and
drops anonymous traffic.
If traffic logs contain no associated user data for unauthenticated
endpoints, Policy Optimizer recommends the predefined keyword unknown,
allowing you to build a specific rule for unauthenticated device
access.
A minimum threshold of 75% is required to associate individual users with
a user group—at least 75% of the user group's resolved user IDs must
appear in the log data for the group to be recommended.
Policy Optimizer does not recommend additional users beyond those already
permitted by the original rule. Recommendations only refine the rule to
be more specific.
If CIE is unavailable, source user optimization is skipped and the
original rule's Source User field is preserved unchanged.
Click Users in the recommendations panel to view the full list of users in
a side panel. For recommendations where the source user is unknown, click
Unknown User to open Log
Viewer and review the associated traffic.
Applications
Replacing port-based rules with App-ID policies is central to the optimization.
Policy Optimizer observes raw application signatures in traffic logs and builds
granular application policies:
Observed applications are consolidated and recommended as defined
application groups, application filters, or predefined Applipedia
containers where applicable.
Policy Optimizer automatically detects and includes any underlying
application dependencies required for the observed applications to
function properly.
Traffic involving unknown applications (such as unknown-tcp or
unknown-udp) is categorized separately, generating isolated rules so you
can investigate unidentified traffic patterns.
Service
The service field is evaluated in relation to the detected applications:
If all detected applications used their standard protocol and ports,
Policy Optimizer recommends setting the service field to
application-default (if the original value was any). This ensures
that applications cannot run on non-standard ports.
If applications ran over non-standard ports, Policy Optimizer retains the
original service object configurations to prevent breaking legacy
application flows.
Tags
Policy Optimizer automatically applies tags to help you identify original and
optimized rules in your Security policy:
Clustering and Rule Formulation
In complex environments, a single overly permissive rule may serve multiple
distinct functions. For example, allowing specific users to access IT
applications and different users to access HR applications. Instead of replacing
the original rule with one large, combined rule, Policy Optimizer clusters
observed traffic into distinct groups based on IP networks and application
categories. This produces multiple specific, easy-to-read rules that together
cover all necessary business traffic while closing broad security loopholes. As
a safeguard, a recommended optimized rule never allows traffic that was not
already permitted by the original rule.