Cisco Security Cloud Control: Secure Firewall Management

PDF

Cisco Security Cloud Control: Secure Firewall Management

Common Policy Analyzer and Optimizer concepts

Want to summarize with AI?

Log in

Find details about common Policy Analyzer and Optimizer concepts. Policy Analyzer and Optimizer uses these shared concepts across access control policy analysis and NAT policy analysis.


Policy Analyzer and Optimizer uses these shared concepts across access control policy analysis and NAT policy analysis.

Table 1. Common Policy Analyzer and Optimizer concepts

Concept

Common behavior

Policy-type difference

Data source

A Cloud-Delivered Firewall Management Center or an On-Premises Firewall Management Center selected in Policy Analyzer and Optimizer.

The Access Control tab can be used for supported On-Premises Firewall Management Center data sources. The Network Address Translation tab is available only when Network Address Translation Policy Analyzer and Optimizer is enabled through AgenticOps for the selected data source.

Sync

Fetches current policy inventory and metadata, including newly created, deleted, or modified policies.

Sync does not, by itself, create a new analysis summary. If the policy changed after the last analysis, run analysis again or wait for scheduled analysis.

Analysis

Evaluates selected policies and produces policy health information, observations, and report data.

Access control Policy Analyzer and Optimizer evaluates access control rule and object findings. Network Address Translation Policy Analyzer and Optimizer evaluates NAT rule shadowing and redundancy.

Reporting

Provides a downloadable analysis report after analysis completes.

Access control Policy Analyzer and Optimizer also provides remediation reports after supported remediation is applied.

Remediation

A workflow that stages selected changes and applies them only when you select Apply Remediation.

Available for access control policies. Network Address Translation Policy Analyzer and Optimizer does not provide an Apply Remediation workflow.

You can stage remediation for an entire anomaly category, selected observations within a category, or individual rules within an expanded observation.

You can also select individual rules within an expanded observation. Using the suggested remediations, you can disable or delete selected Duplicate Rules and Expired Rules, remove selected fully overlapped objects from rules, and merge selected Mergeable Rules.