in this video we'll see how to clean up
and optimize your Juniper firewall
policies without Bozek the first thing
you want to do is log into the algo sex
suite here you can see a list of all the
firewalls and devices that make up your
network for this demonstration we'll
choose a Juniper firewall once we're on
the Juniper firewall page will choose
policy optimization here you'll see a
long list of categories offering
different types of options to clean up
and optimize your network first we'll
look at unused rules here you'll see a
list of rules that are on the firewall
but are not in use to eliminate clutter
we'll want to disable them this is easy
to do without a second all you need to
do is check the boxes of the unused
rules and then click disable selected
rules next we'll look at covered rules a
covered rule is when you have one or
more rules that cover another rule this
makes that rule obsolete in this case
you can also easily disable them by
clicking on the disable selected rules
button the duplicate objects option will
help you uncover two or more policy
objects that point to the same ip
address or to the same set of IP
addresses next we'll briefly take a look
at the intelligent Policy tuner here
we'll take a deeper dive into the
objects to understand what's in use and
how much is in use so for example here
we can see a service defined as any
but as you can see by this icon rarely
any traffic goes through this rule based
on the traffic logs we can see that the
traffic only uses these services here
we'll recommend changing the object any
to a new object consisting of only these
services that are actually hitting the
rule
lastly we'll look at rule reordering you
can see that in this example more
traffic goes through this first rule
than the second if we simply switch the
placement of the rules will enhance the
firewall performance by 75% this has
been a short video on how to clean up
and optimize your Juniper firewall
policies with the outlet X solution to
learn more go to a Luther comm and
schedule a demo today thanks for
watching
you