Troubleshoot Approved Policies
Approved policies are not being carried forward
If approved policies are not being carried forward as expected, make sure the Carry over approved policies option is selected in the advanced and/or default configuration settings for automatic policy discovery.
Finding conversations that are excluded from policy generation
During automatic policy discovery, any conversations that match the criteria for an existing approved policy are excluded from the policy generation. This omission prevents redundant policies covering the same conversations from being generated. This process differs from the exclusion filters, see Exclusion Filters, in which you define matching filters instead of policies. Exclusion filters prevent matching conversations from being visible to all parts of automatic policy discovery.
Note that while redundant policies are not generated from these conversations, the conversations are still considered when automatic policy discovery analyzes and generates clusters.
To see which conversations are excluded from automatic policy discovery by existing approved policies:
In the conversations view (See Conversations), use the excluded flag to filter conversations. You can also explore which existing approved policies result in the exclusion of these conversations in the policy details view that opens on the right side of the page when you click the ports and protocols link in a policy, then click the exclusion icon next to the conversation. (Hover over the icons to find the right icon.)