Configuration changes that require deployment
Cloud-Delivered Firewall Management Center marks out-of-date policies with red status text that indicates how many of its targeted devices need a policy update. Redeploy the policy to the devices to clear this status.
Deployment required
You must deploy changes after these configuration updates:
-
Modifying an access control policy: any changes to access control rules, the default action, policy targets, Security Intelligence filtering, advanced options including preprocessing, and so on.
-
Modifying any of the policies that the access control policy invokes: the SSL policy, network analysis policies, intrusion policies, file policies, identity policies, or DNS policies.
-
Changing any reusable object or configuration used in an access control policy or policies it invokes:
-
network, port, VLAN tag, URL, and geolocation objects
-
Security Intelligence lists and feeds
-
application filters or detectors
-
intrusion policy variable sets
-
file lists
-
decryption-related objects and security zones
-
-
Updating intrusion rules (SRU/LSP) or the vulnerability database (VDB).
-
Upgrading managed devices.
You can change some of these configurations from multiple places in the web interface. For example, you can modify security zones using the object manager (), but modifying an interface type in a device configuration () can also change a zone and require a deployment.
Deployment not required
These updates do not require a deployment:
-
Security Intelligence updates to feeds and the global Block or Do Not Block lists.
-
URL filtering data updates.
-
Geolocation database (GeoDB) updates.