Configure access control preferences

You can track changes to access control rules by allowing or requiring users to comment when they save. This allows you to assess why critical policies in a deployment were modified. By default, this feature is disabled.

Configure object optimization to evaluate and optimize network or host policy objects that are used in rules. The system then creates associated network object groups on the device. For more information, refer to Object-group optimization.

Procedure


Step 1

Choose Administration > Configuration > Access Control Preferences.

Step 2

From the Comments on rule change list, choose an option:

  • Disabled: Disables comments for access control rule changes.

  • Optional: Allows users to optionally add a comment when they change an access control rule.

  • Required: Requires users to add a comment when they change an access control rule.

Step 3

From the Object-group optimization list, choose an option:

  • Enabled: Enables object-group optimization. The setting takes effect after deployment.

  • Disabled: Disables object-group optimization.

Warning
For the first deployment to a threat defense device after you enable object-group optimization, the device can take several minutes to an hour to reevaluate the policy configuration and optimize object groups. CPU utilization on the device can also increase. Schedule the deployment during a low-traffic period or a maintenance window.

Step 4

Click Save.


What to do next

Deploy the access control policies for object-group optimization to take effect.