Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 
 

Compare Security Policy Versions

Compare two different versions of a security policy to view the following changes between the policy versions:

  • Added, deleted, or modified rules.

  • Changes made to rule positions, such as rules added or removed from a group.

  • Rules that are unchanged.

  • Object-level changes such as changes in source, destination, application or services, action, security subscriptions, and options.

You can use the changes marked in the two compared security policy versions to make decisions such as rolling back the policy to a previous version, modifying the policy configurations, and deploying the policy again.

To compare two different versions of a policy:
  1. Select Security > Security Policies.

    The Security Policies page is displayed.

  2. Select the security policy and click More > Manage Policy Versions.

    The security policy versions page is displayed.

  3. Select the security policy versions to compare and click Compare.

    You can compare two versions of a security policy.

The Policy Diff page is displayed.

You can view the differences using the color-coded legends and the count of the security policy rules that were added, deleted, modified, and moved according to the guidelines provided in Table 1.

Table 1: Guidelines for Compare Policy Versions
Items to view Description

Added rules

New security policy rules are displayed with green background.

Firewall rule configuration interface showing rule 3: Deny all traffic from any source to any destination for any application.

Deleted rules

Deleted security policy rules are displayed with red background.

Firewall rule configuration interface: Rule P1-Rule-71_copy_1 set to deny all traffic from any source to any destination. Security features disabled.

Revised rules

Modified security policy rules are displayed with orange background.

Firewall configuration interface with a table listing security rules for managing network traffic. Key elements: Rule Name, Sources, Destinations, Applications/Services, and Action. The rule is highlighted in light orange, indicating its status.

Unchanged rules

Unchanged security policy rules are shown with white background.

Click UNCHANGED RULES to expand the row and view the unchanged rules.

Firewall rule table section with 86 unchanged rules; Seq, Rule Name R5 and R6, Sources Any, Destinations Any, Applications/Services Any, Action Deny, Security Subscriptions IPS, Content Security, Decrypt, SecIntel, Anti-malware.

Moved rules

Security policy rules moved to another position, added to a group, or removed from a group are shown with dotted lines.

Hover your cursor over the Seq field of security policy rule to view the previous position or group.

Firewall rule configuration interface showing rule R1 denying all traffic from any source to any destination for any application or service.

Object-level changes in revised rules

Object-level changes in security policy rules are shown using different options in the comparison report.

  • Click Rule Diff to view the object-level changes.

  • Click View Detailed Rule Diff to view detailed object-level differences for the entire policy.