Configuration deployment
Configuration deployment is the process of deploying configuration and policy updates to your Fireall Threat Defense devices after you make changes. This process allows you to apply changes to multiple components including device configurations, security policies, and network discovery settings.
Deployment components
Deploying updates applies to these components:
-
Device and interface configurations
-
Device-related policies, such as NAT, VPN, QoS, and platform settings policy
-
Access control and related policies: DNS, file, identity, intrusion, network analysis, prefilter, SSL
-
Network discovery policy
-
Intrusion rule updates
-
Configurations and objects associated with any of these elements
You can configure the system for automatic deployment by scheduling a deploy task or by setting the system to deploy when importing intrusion rule updates. Automating policy deployment is especially useful if you allow intrusion rule updates to modify system-provided base policies for intrusion and network analysis. Intrusion rule updates can also modify default values for the advanced preprocessing and performance options in your access control policies.
You can view deployment status in the Notifications pane.