Cisco Secure Access Help

PDF

Cisco Secure Access Help

Optimize Access Policies

Want to summarize with AI?

Log in

The Policy Optimization feature in Cisco AI Assistant for Secure Access streamlines access policies by detecting duplicate and shadow rules. You can easily scan for these anomalies, review reports, and disable or delete unnecessary rules to enhance policy efficiency.


The Cisco AI Assistant for Secure Access helps you optimize policy by identifying duplicate and shadow rules.

  • Duplicate rules are Private Access or Internet Access rules with the same source, destination, or security controls.

  • Shadow rules are Private Access or Internet Access rules that match the criteria of a preceding rule.

Procedure

  1. Click the Cisco AI Assistant icon in the Secure Access toolbar to open the AI assistant.

    Image displaying the Cisco AI Assistant icon
  2. Enter a prompt to find duplicate policies or shadow policies.

    The following table displays some example prompts and the respective scan type that the AI Assistant performs.

    Prompt Scan Type
    Optimize rules for my org Scan for any duplicate or shadow rule anomalies applied to any source or destination in your Secure Access organization.
    Find duplicate policies Scan for any duplicate rule anomalies applied to any source or destination.
    Show me shadow rules for the Engineering group Scan for any shadow rules applied to users in the Engineering group.
    Any rules to optimize for George? Scan for any rule anomalies rules applied to the user George.
  3. The AI Assistant prompts you to confirm the product. Select SSE for Cisco Secure Access.

    Image displaying SSE option selection for Secure Access
    Note
    This step is applicable if you are using Cisco AI Assistant within Cisco Security Cloud Control.

    Once the scan begins, the Cisco AI Assistant will inform you that the analysis may take some time to complete.

    Note

    The scan may take some time to complete depending on factors such as the size of your policy set, the number of rules, and the complexity of your organization. Please allow sufficient time for the analysis to finish.

    Image displaying sample response for rule optimization prompt

    Once the scan is complete, the policy optimization report will be made available in the AI Notifications menu. Navigate to the bell icon to review completed policy optimization scans.

    Image displaying AI Notifications tab of the Cisco AI Assistant

    Each scan result shows any duplicate and shadow rules detected for the specific prompt.

    Image displaying the optimization scan result

    Submit a follow up prompt or question for more detail about the scan, or choose from the options in the completed scan menu:

    • Disable rules or Delete rules: Choose to Disable or delete all anomalies, duplicate rules only, or shadow rules only.

      Image displaying the disable rule options
      Note
      Before disabling or deleting any detected duplicate or shadow rules, assess the potential impact on your access policy. This precaution helps prevent accidental disruptions and ensures that only the intended rules are modified.
    • Click Details to see more information about rule sources, destinations, types of anomalies, and more.

      Image displaying the optimization scan details
    • Select one or more rules in the anomaly details menu to disable or delete the rules.

      Image displaying the options for disabling or deleting selected rules
    • Click Download report to export scan results to a tab-separated value (tsv) file that presents results in a table.