Configure interface object optimization
Interface object optimization enables the system to deploy a single rule per access control/prefilter rule instead of generating separate rules for each source/destination interface pair, simplifying device configuration and improving deployment performance.
During deployment, interface groups and security zones used in the access control and prefilter policies generate separate rules for each source and destination interface pair. Enabling interface object optimization deploys a single rule per access control or prefilter rule. This approach simplifies device configuration and can improve deployment performance. If you select this option, also select the Object Group Search option to reduce evice memory usage.
Interface object optimization is disabled by default. You can enable it on one device at a time; you cannot enable it globally.
Note | If you disable interface object optimization, the system deploys existing access control rules without using interface objects. This process might take longer. If object group search is enabled, its benefits do not apply to interface objects, and the device's running configuration might show expanded access control rules. If this expansion requires more memory than is available, the device can become inconsistent, which may affect performance |
Before you begin
Model support—Firewall Threat Defense
Procedure
Step 1 | Choose . |
Step 2 | Next to the Firewall Threat Defense device where you want to configure the rule, click the Edit ( |
Step 3 | Under the Device tab, click Edit ( |
Step 4 | Check Interface Object Optimization. |
Step 5 | Click Save. |