Policy Optimizer not available in PAN-OS 12.1

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Policy Optimizer not available in PAN-OS 12.1

L1 Bithead

Hello there,

with the brand-new PA-520 and PAN-OS 12.1.4-h3 is the Policy Optimizer missing (see my screenshots). I have found this info

 

"(PAN-OS 12.1.2 and later versions) To ensure the best performance, customize your view to display the Policy Optimizer, only when you need it. The system fetches data for this component on-demand, which prevents automatic data fetching for the columns and avoids system slowdowns." (Security Policy Rule Optimization)

 

The checkbox "Policy Application Usage" is checked in the rulebase settings, which is the way to disable/enable the Policy Optimizer (https://docs.paloaltonetworks.com/copilot?originalUrl=https%3A%2F%2Fdocs.paloaltonetworks.com%2Fngfw...)

 

Where else can I "customize the view"?

 

BR

1 accepted solution

Accepted Solutions

Hi Pavel, thank you. All your points are okay with my firewall.

We have found the solution. While in 11.x the Policy Optimizer at the bottom left corner includes all modes, it's also possible to reach the "Applications & Usage" window for each rule with the column "apps seen". This column isn't automatically added in 12.1, and after we have added it, we are able to access this "Application & Usage" window by clicking the value in the "apps seen" column.

I really liked the policy optimizer overview in 11.x, which seems to have been removed in 12.1. But still, this view per rule using the column is better than nothing 🙂

I have attached the screenshots how to access it.

 

BR

View solution in original post

5 REPLIES 5

Cyber Elite

Hello @J.Dhling

 

thanks for post!

 

I think what Palo Alto is referring in the documentation as "customize view" is Step No.6, Point No.4 in this link: View Policy Rule Usage. Do you have a Rule Usage check box enabled?

 

Kind Regards

Pavel 

Help the community: Like helpful comments and mark solutions.

Hi Pavel,

 

thanks for your reply. Yes, both settings from the link are enabled.

I just saw the little arrow on the bottom left corner to expand the "Object: Addresses", "Tag Browser" and "Policy Optimizer", BUT only for unused rules, not for "Rules without Apps", and "unused Apps". See my screenshot below.

 

BR

Cyber Elite

Hello @J.Dhling

 

thank you for reply!

 

Based on information you provided you should meet all the requirements to have Policy Optimizer available. I can only think of below points:

 

  • Could you under POLICIES > Security, navigate (scroll down) to the very bottom. If you do not see any other items other than what you shared in your screen shot, then try to use different browser or incognito mode to eliminate an issue with how browser is displaying the content? It may also help to maximize the browser window and reset the zoom level to 100%.
  • I went through all release notes between your version 12.1.4-H3 and 12.1.8 and I could not find any known issue related to symptom you described. As of now 12.1.4-H3 is preferred version, however I could see in latest version 12.1.8 several GUI related addressed issues. Since we can't eliminate a defect that is not publicly listed in release notes, I would consider to upgrade if you can afford to go outside of PAN recommended version. Before doing an upgrade, I would recommend opening a support case before upgrading solely to troubleshoot this symptom.
  • Are you logged in using a superuser account? If you are using a custom Admin Role, please test with a superuser to exclude an interface-access restriction.
  • Was the change to enable Policy Application Usage committed?
  • Is logging at session end enabled in all policies. The Log at Session End is required for Policy Optimizer to collect application-usage information. However, missing session end logging would normally result in missing or incomplete usage data. It should not make the entire Policy Optimizer interface disappear.

Kind Regards

Pavel

Help the community: Like helpful comments and mark solutions.

Hi Pavel, thank you. All your points are okay with my firewall.

We have found the solution. While in 11.x the Policy Optimizer at the bottom left corner includes all modes, it's also possible to reach the "Applications & Usage" window for each rule with the column "apps seen". This column isn't automatically added in 12.1, and after we have added it, we are able to access this "Application & Usage" window by clicking the value in the "apps seen" column.

I really liked the policy optimizer overview in 11.x, which seems to have been removed in 12.1. But still, this view per rule using the column is better than nothing 🙂

I have attached the screenshots how to access it.

 

BR

Cyber Elite

Hello @J.Dhling

 

thank you for feedback! I see and it makes sense now. I think documentation should have been more clear on this.

 

Kind Regards

Pavel

Help the community: Like helpful comments and mark solutions.
  • 1 accepted solution
  • 237 Views
  • 5 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!