Analyze Cloud-delivered Firewall Management Center Policies

If you have the cloud-delivered Firewall Management Center already provisioned on your CDO tenant, you can readily start analyzing the policies. To provision the cloud-delivered Firewall Management Center on CDO, see Enable Cloud-delivered Firewall Management Center on Your CDO.


When you create a new policy, it might take a while for the Policy Analyzer and Optimizer to fetch the policy details and show up on the Policy Analyzer and Optimizer. Click the refresh () button on the top-right corner to manually refresh the page to see new policies.


Step 1

From the CDO left navigation pane, navigate to Tools & Services > Firewall Management Center—the Services page comes up, with Cloud-Delivered FMC selected by default.

Step 2

Click Policy Analyzer and Optimizer under System on the right pane.

Alternatively, on the left pane, choose Insights > Policy Analyzer and Optimizer. The Showing policy for option at the top-left corner shows which device's policies are displayed; click to switch among cloud-delivered Firewall Management Center and other On-Prem Firewall Management Centers.

Step 3

For analyzed policies, the Policy Analyzer and Optimizer provides an overview of the analysis that includes Total Rules, Observations, Anaysis Status, and Last Modified and Last Analyzed timestamps. You can also see more details on the right pane when you select a policy.

Step 4

Select the policy for which you want to view the analysis details or re-analyze.

The Policy Analyzer and Optimizer automatically analyzes all the policies every 24 hours, and there are high chances that all your policies already got analyzed and details are ready for you to review.

Step 5

Click Re-analyze Policy to manually trigger another analysis.