Software Secure Workload
Activity Configure

View, Compare, and Manage Discovered Policy Versions

Each time you discover policies in a workspace, the version number (v*) assigned to the set of policies increments.

For information, see About Policy Versions (v* and p*).

Procedure

1

Click Defend > Segmentation.

2

Navigate to the workspace.

3

Click Manage Policies.

4

The currently displayed version of the policies generated by automatic policy discovery is shown at the top of the page:

Currently displayed version of policies

If you have already analyzed or enforced policies, the displayed version may be a policy discovery version, an analyzed policy version, or an enforced version.

5

Do one of the following:

Display a different version of the policies generated by automatic policy discovery:

Click the current version and choose a different v* version.

(If you see p* versions, those are analyzed and/or enforced versions, not versions of discovered policies.)

Show policy versions

Important!! See the caveat in the What To Do Next section at the end of this procedure.

View details about a version

  1. Click View Version History at the top of the page beside the current version.

  2. Click the Versions tab to see the versions of discovered policies. (Not the Published Versions tab.)

    The list of versions displays:

    List of generated policy versions with summary information
    Figure 1: List of generated policy versions with summary information
  3. Click the log events link in the version.

  4. Click a link in an event row.

    Available details include statistics, exclusion filters, external dependencies, and configurations for the run.

    Configurations used for particular automatic policy discovery runs
    Figure 2: Configurations used for particular automatic policy discovery runs

Compare two versions to see what has changed:

  1. Click Compare Revisions.

  2. Choose the versions to compare.

  3. For result details, see Comparison of Policy Versions: Policy Diff.

Delete an unwanted version:

Click More button for the version and choose Delete.

You cannot delete the last remaining version generated by automatic policy discovery (v* version).

Export a version:

Click More button for the version and choose Export....

What to do next


 

If you want to preserve previous versions of the discovered policies, always display the current version of the discovered policies when you are done working with older versions.

If the most current version of the discovered policies is not displayed the next time you discover policies for this workspace, older versions may be deleted.

For example, if the most current version of discovered policies is v4, and v2 is displayed when you discover policies again, then the existing v3 and v4 will be deleted and the new discovered policy version will be v3.

This behavior ensures a linear version history, which simplifies reverting to a previous version if desired.

In addition, you can manually create policies only if the latest v* version is displayed.