IoT Policy Optimization Available
The IoT Policy Optimization insight uses flow data to offer customer with activity visibility, which aids in the development of firewall policies for IoT clients. The firewall policies include internal and external destination IP addresses and application pairs, and they are assigned on a customer client type basis. These policies are generated on a daily basis from the last 30 days of aggregate flow data.
You can view the following views:
-
Behavior—View traffic patterns and generate policy recommendations.
-
Policy—Compare existing policies with optimizer suggestions.
To access the IoT Policy Optimization Available insight, complete the following steps:
-
Access the Insights page. For more information, see Accessing Insights Page.
-
Click the IoT Policy Optimization Available tab.
The IoT Policy Optimization page lists IoT clients that support policy optimization.
Figure 1: IoT Policy Optimization Available Insight
In the IoT Policy Optimization page, you can view the following details:
Table 1: IoT Policy Optimization Parameters
Parameter
Description
Source Role
Displays the role of the client device.
Clients
Displays the number of clients eligible for policy optimization.
Policy Rules
Displays the number of policy rules created for the client.
Behavior Coverage(%)
Displays the percentage of flows affected by the policy.
-
Click on the Source Role to view the IoT Policy Optimizer window.
Figure 2: IoT Policy Recommender - Internal Sample
In the IoT Policy Optimizer window, you can view the following details:
-
Behavior Mapping—The ribbon chart displays a pictorial view of all the internal, external and common traffic from the client source to destination IP address or subnets. The chart volume is distributed based on the session count.
-
Policy Generator - External Tab—Displays destinations accessed by IoT devices outside the enterprise network.
Table 2: Policy Generator - External Tab Parameters
Parameter
Description
Source Role
Displays the role of the client device.
URL or Destination
Displays the external domain dame or IP address accessed by the IoT device.
Service/Application
Displays the service or application name. For example, HTTPS, TCP, and RTSP.
Session Count
Displays the sessions observed for the destination.
-
Policy Generator - Internal Tab—Displays communication between IoT devices internal enterprise devices.
Table 3: Policy Generator - Internal Tab Parameters
Parameter
Description
Source Role
Displays the role of the client device.
Destination IP
Displays the internal IP address or subnet accessed by the IoT device.
Service/Application
Displays the service or application name. For example, HTTPS, TCP, and RTSP.
Session Count
Displays the number of internal sessions.
-
Policy Generator - Common Tab—Displays destinations shared across multiple IoT roles.
Table 4: Policy Generator - Common Tab Parameters
Parameter
Description
Source Role
Displays the role of the client device.
Destination IP
Displays the IP address accessed by the IoT device.
Destination Domain
Displays the domain name associated with the destination IP.
Service/Application
Displays the service or application name. For example, HTTPS, TCP, and RTSP.
Session Count
Displays the number of session counts.
-
-
Click the Policy tab.
The Policy tab is displayed.
Figure 3: Policy Tab Sample
This tab displays the existing policies and compares them with optimizer-generated suggestions, enabling informed policy updates. In this tab, you can view the following information:
-
Existing Policies—Displays policies already configured for the selected scope. You can view the following parameters:
Table 5: Existing Policies Parameters
Parameter
Description
Name
Displays the name of the existing policy. Click on the role name to view the existing policy details.
Rules
Displays the number of rules in the policy.
Assigned Device Function
Displays the service or application name.
Session Count
Displays the number of session counts.
-
Suggestions—Displays policy recommendations generated from observed client behavior. You can view the following parameters:
Table 6: Suggestions Policies Parameters
Parameter
Description
Parameter
Description
Source Role
Displays the IoT role. Click on the role name to view the existing policy details.
Destination
Displays the suggested destination domain or IP.
Service/Application
Displays the IoT device function to which the policy is applied.
Assigned Scope
Displays the network, site, or location where the policy is applied.
-