Address Low-Confidence Policies
After automatic policy discovery, confidence ratings indicate the accuracy and appropriateness of each discovered policy for each service (port and protocol) specified in the policy.
To identify low-confidence discovered policies:
-
Navigate to the applicable scope and workspace and click Manage Policies.
-
Click the Policies tab.
-
Click the Ungrouped Policy List View button.
-
Click the Confidence column heading to sort the list of policies by confidence level.
-
Click the value in the Protocols and Ports column to open a panel on the right side of the window.
-
In the Protocols and Ports section, the color of each C indicates the confidence for each service (port and protocol) specified in the policy.
To interpret the confidence level, hover over the C.
-
Look for low-confidence indicators for any services in the list.
-
If applicable, delete or edit unwanted policies, or add additional policies.
To view the confidence levels for a particular policy:
-
In the Policies tab, click the value in the Protocols and Ports column for that policy.
The Policy Side View panel opens at the right side of the window.
-
In the Protocols and Ports section, the color of each C indicates the confidence for each service (port and protocol) specified in the policy.
To interpret the confidence level, hover over the C.
Flow Direction and Policy Confidence
The accuracy of discovered policies depends on correct identification of the flow direction. If flow direction is incorrectly identified, the confidence rating of automatic policy discovery results may be reduced. For information about determination of flow direction for the conversation(s) analyzed for the creation of the policy, see Client Server Classification.