Compare Security Policy Versions
Compare two different versions of a security policy to view the following changes between the policy versions:
-
Added, deleted, or modified rules.
-
Changes made to rule positions, such as rules added or removed from a group.
-
Rules that are unchanged.
-
Object-level changes such as changes in source, destination, application or services, action, security subscriptions, and options.
You can use the changes marked in the two compared security policy versions to make decisions such as rolling back the policy to a previous version, modifying the policy configurations, and deploying the policy again.
The Policy Diff page is displayed.
You can view the differences using the color-coded legends and the count of the security policy rules that were added, deleted, modified, and moved according to the guidelines provided in Table 1.
| Items to view | Description |
|---|---|
|
Added rules |
New security policy rules are displayed with green background. ![]() |
|
Deleted rules |
Deleted security policy rules are displayed with red background. ![]() |
|
Revised rules |
Modified security policy rules are displayed with orange background. ![]() |
|
Unchanged rules |
Unchanged security policy rules are shown with white background. Click UNCHANGED RULES to expand the row and view the unchanged rules. ![]() |
|
Moved rules |
Security policy rules moved to another position, added to a group, or removed from a group are shown with dotted lines. Hover your cursor over the Seq field of security policy rule to view the previous position or group. ![]() |
|
Object-level changes in revised rules |
Object-level changes in security policy rules are shown using different options in the comparison report.
|




