Configure initial plan device group conditions

This topic explains how to configure custom conditions for which device group to query during initial planning.

Create new initial plan conditions

When a traffic change request enters the Initial Plan stage, FireFlow determines which devices are relevant for the change request with an AFA traffic simulation query on a group of devices. By default, the traffic simulation query is always run on the ALL_FIREWALLS group. If desired, you can specify conditions for when the query should run on a different AFA defined device group.

Note: Conditions configured for the initial plan device group in the FireFlow web interface take precedence over any conditions specified with the GetFirewallGroupName (see GetFirewallGroupName) hook.

Do the following:

  1. Log in to FireFlow for configuration purposes. For details, see Log in for configuration purposes.

  2. In the main menu, click Configuration.

    The FireFlow Configuration page appears.

  3. Click Conditional Logic.

    The Select a condition page appears.

  4. Click the Initial Plan tab.

    The Initial Plan tab appears.

  5. Click .

    The Create device group for initial plan custom logic window appears.

  6. Complete the fields using the relevant information in Initial Plan Custom Logic Fields (see Initial Plan Custom Logic Fields).

  7. Click Save.

Back to top

Initial Plan Custom Logic Fields

In this field...

Do this...

Enter Condition Name

Type a name to represent the condition.

Enter Description

Type the description of the condition.

Enabled

Select this check box to enable the condition.

Apply this condition to

Select the relevant workflows. The selected workflows appear in the Target Workflow list.

To remove a status, click the status in the Target Workflow list.

When

Define the condition by selecting the condition type in the drop down menu and completing the relevant fields.

  • For the Custom Field condition type, select the field, select the boolean operator, and type the value for the field.
  • For the Traffic condition type, select the relevant endpoint(s), select the boolean operator, and type the IP address, range or CIDR for the field.

Note: The Traffic condition type is only for traffic change request workflows.

Device group for Initial Plan is

In the drop-down list, select the device group which should be used for the Initial Planning traffic simulation query for change requests which meet the defined conditions.

Back to top