Cisco Security Cloud Control: Secure Firewall Management

PDF

Cisco Security Cloud Control: Secure Firewall Management

Prerequisites to use Policy Analyzer and Optimizer

Want to summarize with AI?

Log in

Before you use Policy Analyzer and Optimizer, verify the prerequisites that apply to your policy type and data source.


Before you use Policy Analyzer and Optimizer, verify the prerequisites that apply to your policy type and data source.

  • The On-Premises Firewall Management Center must be integrated with Security Cloud Control.

    Note

    In the On-Premises Firewall Management Center, navigate to Integration > Cisco Security Cloud and check the Enable Policy Analysis & Optimization checkbox after integrating with the Cisco Security Cloud.

Prerequisites to use Policy Analyzer and Optimizer for access control policy

  • Access control policy analysis is supported on the On-Premises Firewall Management Center operating on Version 7.2 or later. The Cisco-recommended Version is 7.6 or later, because these versions support cross-launch to Policy Analyzer and Optimizer directly from On-Premises Firewall Management Center.

  • Access control policy to be analyzed must be associated with a Firewall Threat Defense device that is managed by an On-Premises Firewall Management Center integrated with Security Cloud Control.

Prerequisites to use Policy Analyzer and Optimizer for Network Address Translation

  • NAT policy analysis is supported on the On-Premises Firewall Management Center operating on Version 7.6 or later.

  • Network Address Translation Policy Analyzer and Optimizer availability also depends on AgenticOps being enabled for the selected tenant and data source. For more information, refer to Enable AgenticOps Insights.

  • Enable AgenticOps for the Cloud-Delivered Firewall Management Center or On-Premises Firewall Management Center data source that you want to analyze. Choose Insights & Reports > Settings > Policy Analyzer and Optimizer > Data Sources and enable AgenticOps for the management center you want.

Note

If an On-Premises Firewall Management Center is running a version earlier than 7.6, access control Policy Analyzer and Optimizer may still be available for analyzing access control policy, but Network Address Translation Policy Analyzer and Optimizer is not available for that data source.