Automate NGFW configuration variable resolution during onboarding using Site
Management in Strata Cloud Manager.
| Where Can I Use This? | What Do I Need? |
|
|
Contact your account representative if you are interested in
enabling this feature.
One of these licenses:
Roles needed:
Network Administrator Superuser Business Admin
|
Site Management in Strata Cloud Manager streamlines Next-Generation Firewall (NGFW)
deployment by automating configuration variable resolution. This feature introduces a
"Site" as a core entity for NGFW deployment, abstracting device complexity in your
environment. You define reusable properties and rules to generate specific variable
values for individual devices, eliminating manual operations and standardizing your
provisioning process.
Site Management improves NGFW deployments by ensuring consistency and reducing errors,
especially at scale. Previously, configuring settings like IP addresses or hostnames
manually for each device often caused inconsistencies and increased administrative
effort. Site Management automates these calculations and standardizes value generation
across NGFWs, reducing configuration drift and enhancing scalability for large
deployments.
Site Management operates by centralizing your configurations. You define
Properties — customer-defined metadata consisting of user-specified keys and values
that describe each site's unique characteristics (such as location, region, or site
ID) — and assign specific property values to individual Sites. These site-specific
values are then used by Onboarding Rules, which contain Variable Resolution Rules.
The Site Manager component dynamically calculates complex configuration details,
such as derived IP addresses or hostnames, by substituting variables with site
property values.
The workflow begins when you define Properties, Site Properties Groups, Sites, and
Onboarding Rules within Strata Cloud Manager. An installer then selects a target
site while installing the NGFWs. Strata Cloud Manager resolves the configuration in
accordance with the variable resolution rules defined by the admin. This process
includes Onboarding Properties as customizable metadata and Variable Resolution Rules
that support string substitution and bit operations for precise IPv4 address
generation. A Claim process then ties a physical or virtual NGFW to a
pre-configured Site, triggering automated variable resolution and provisioning
through Strata Cloud Manager.
This feature is only available during the onboarding of NGFWs.
This feature exclusively supports IPv4 for all IP address fields,
variables, and resolution rules; IPv6 is not supported.
A site is restricted to being claimed by one single device.