Note Some tasks in this topic might not apply to your feature. Refer to the tasks relevant to you.
You create a policy version by taking a snapshot of another policy. You can create versions for all types of policies including All Devices, Group, Device, and Device exceptions.
The maximum number of versions maintained for any policy is 60. If the maximum limit is reached, you must delete the unwanted versions before saving a new version. Versioning and rollback are independent operations for each policy.
For example, if you take a snapshot of a group firewall policy, or roll back to a previous firewall policy version, it does not change the version for all device policy rules; you must separately version each policy rule.
Creating Policy Snapshots
To create a policy version:
A list of actions appears.
The Manage Version page appears.
The Snapshot Policy page appears.
Note During policy publish, Security Director takes an automatic snapshot of the policy.
Managing Policy Versions
You can view or manage all available versions of a selected policy. You can perform the following tasks on the snapshots:
Roll back to a specific version.
View the differences between any two versions (including the current version) of the policy.
Delete one or more versions from the system.
Rolling Back Policy Versions
To roll back the selected version so it becomes the current version:
A list of actions appears.
The Manage Version page appears.
The rollback operation replaces all the rules and rule groups of the current version with rules and rule groups from the selected version. For all the shared objects, Object Conflict Resolution (OCR) is done. If there are any conflicts between the versioned data and the current objects in the system, the OCR window is displayed.
Deleting Policy Versions
To delete a policy version:
A list of actions appears.
The Manage Version page appears.
A warning message is displayed.
The selected policy version is deleted.
© 2020 Juniper Networks, Inc. All rights reserved