On this page
Decommissioning Network Objects
|
|
This topic is intended for SecureChange requesters, responsible for creating change requests in SecureChange. |
|
|
This KC page is intended for SecureChange handlers who are responsible for processing change requests. |
Overview
Decommissioning a network object removes a server, subnet, or address range from every firewall rule where it appears, so that rule bases stay accurate and unused entries don't accumulate as risk.
Requestor
The requestor initiates the change request to decomission one or more network objects using a workflow that includes a Decommission Network Object field. Remove specified servers or other network objects from all firewall rules.
When defining the network object, requestors can add a CSV file or manually add one or more network addresses, subnets, or ranges.
Handler
After the requester defines the network object to decommission, based on the properties configured for the workflow and the step, the step handler can use the different tools to evaluate the impact of the request and get and verify implementation suggestions.
-
Evaluate the impact of the request (Impact Analysis)
-
Get suggested rule changes (Designer)
-
Verify if suggested changes are implemented (Verifier)
Define network object for decommissioning
Specify the network object request to decommission to start the process. The Decommission Network Object field can be in the first or any other step in the workflow.
Requesters can manually define one or network objects, or add a file with a predefined list of objects.
Subnet prefix in network object
By default, when a subnet prefix is not specified, SecureChange assigns it based on the network class. For example, 10.1.0.0 is assigned as 10.1.0.0/16.
From TOS 5.3, to minimize the risk of unintentional large-network decommission, you can change this default so that SecureChange always assigns /32 when no subnet prefix is specified. For implementation details, contact Tufin Support.
Steps
-
Select SecureChange > Requests, and then select the request.
-
To import a predefined list of network objects to decommission, click Attachments > Add, and then select the file to add it.
-
Click the Edit icon in the Network Address, Subnet or Range field.
-
Do the following:
-
In Multi-Domain Integrated mode, select the domain. Selecting Default as the domain, finds the specified server in any domain.
-
Enter a network address, subnet, or range.
Addresses with non-continuous network masks are not supported.
Define a server as a name from a monitored firewall, a DNS name, or an IP address.
-
-
Click OK.
SecureChange validates the DNS and IP address values.
-
Click in the Comment field, and enter a comment. For example the purpose of decommissioning the specified object(s).
-
To create a ticket for the request, click Submit.
Processing decommission tickets
Once a request is submitted, depending on how the ticket's workflow is set up, the step handler can use workflow tools to investigate the request's impact, get suggested rule changes, and confirm that those changes were implemented. The results depend on the size of the impacted rule set.
Open decommission ticket
Select SecureChange >
Tickets , and open the required ticket.
Investigate impact analysis
Run Impact Analysis to see where the servers to be decommissioned are used in firewall rules across all firewalls.
-
Click Impact Analysis.
-
Review the firewall rules where the servers are used, including the relevant domains when you are in Multi-Domain mode.
Use Designer for rule change suggestions
Run Designer to view suggestions on how to change the firewall rules to decommission the network objects. This may include removing the object from rules or groups, or removing a rule entirely if it is no longer relevant.
-
Click Designer.
-
Review Designer suggestions:
The instructions can include:
-
Removing e a rule
-
Removing a server from the source or destination of a rule
-
Removing a group from a rule
Review the original Decommission Network Object request below the list of instructions.
-
-
Manually follow the instructions provided by the Designer.
For devices where provisioning is supported, Designer can implement these changes.
Verify decommission changes
Run Verifier to verify that the network objects were removed from the firewall rules.
Handling large rule sets
When Impact Analysis, Designer, or Verifier find that a ticket affects more than the system threshold of 3000 rules, only rules from devices with the total rule count under the threshold appear in the results; devices that exceed it appear without their rules.
This behavior helps prevent performance and stability issues during automation When the threshold is reached, the tool's status indicator turns yellow, with a message noting that not all targets or rules are included.
You can rerun Impact Analysis, Designer, or Verifier on the same ticket to process the remaining rules, or create a new decommission ticket for them.
To change the threshold, contact Tufin Support.
Related topics
Was this helpful?
Thank you!
We’d love your feedback
We really appreciate your feedback
Send this page to a colleague








