Cisco Security Cloud Control: Secure Firewall Management

PDF

Cisco Security Cloud Control: Secure Firewall Management

About Policy Analyzer and Optimizer

Want to summarize with AI?

Log in

Learn how Policy Analyzer and Optimizer in Security Cloud Control Firewall Management analyzes access control and NAT policies, identifies rule anomalies, reports optimization opportunities, and supports remediation where available.


AgenticOps for firewalls provides operational insights and tools that help improve firewall management, policy hygiene, and deployment readiness. One such capability is Policy Analyzer and Optimizer, which uses an algorithmic approach to evaluate firewall policy rules and identify anomalies such as duplicate, shadowed, redundant, or otherwise optimizable rules. For more information, refer to AgenticOpsInsights to know more about the various other functionalities that AgenticOps provides.

Secure Firewall Threat Defense devices with extensive policies may have numerous duplicate or shadowed rules. Such large policies with unoptimized rulesets can lead to excessive consumption of device memory, delayed loading of rules, and long search duration, resulting in inefficient security policy enforcement, reduced network speeds, and extended deployment durations.

Policy Analyzer and Optimizer is an intelligent Security Cloud Control Firewall Management service that analyzes firewall policies, detects rule anomalies, and helps you understand where a policy can be optimized. Policy Analyzer and Optimizer supports access control policies policies for Cloud-Delivered Firewall Management Center and supported Security Cloud Control-managed On-Premises Firewall Management Center data sources.

In addition, Policy Analyzer and Optimizer can do the following:

  • View policy health and optimization opportunities for the selected management center data source.

  • Analyze policies on demand or rely on scheduled analysis that runs every 24 hours.

  • Download analysis reports as PDFs after analysis completes.

  • Use Access Control Policy Analyzer and Optimizer remediation workflows where supported.

  • Stage and apply remediation for an entire anomaly category, selected observations, or individual rules within supported observations.

  • Use Network Address Translation Policy Analyzer and Optimizer findings and AgenticOps insights to investigate NAT policies that contain optimizable rules.

Supported policy types

Security Cloud Control Firewall Management performs anomaly analysis on the following policy types:

Table 1. Supported policy types for Policy Analyzer and Optimizer

Policy type

Use this section when

Current scope

Access control policy

You want to analyze access control policies, review access control findings, and apply supported remediations.

Analysis, remediation, reporting, remediation history, and policy insights.

Network address translation policy

You want to analyze NAT policies for shadowed and redundant NAT rules.

Analysis and reporting for fully shadowed and fully redundant NAT rules. NAT remediation is not available in this release.