Steps involved in copying the entire Visual Policy Manager (VPM) from one Edge SWG (ProxySG) to another. This is helpful when customer needs to have identical policies on couple of Edge SWG (ProxySG) (or ASGs) and don't have Management Center to perform this. This will help in avoiding the pain of recreating the same objects and rules on the proxies.
NOTE: These steps help in only copying the policies configured on the VPM. It doesn't make any configuration changes on the Master Edge SWG (ProxySG).
Example below shows the copying of VPM from one Edge SWG (ProxySG) to another
Requirements/Limitations
Overall view on steps being performed
In Edge SWG (ProxySG), Visual Policy Manager (VPM) provides an easy graphical interface for creating layers and rules within. VPM consists of 2 components, VPM-XML and VPM-CPL. VPM-XML is the look and feel one will experience when you open the Visual Policy Manager. This holds the information on the layers, their order, all objects created, VPM policy based category lists etc. VPM-CPL is the policy file which automatically gets generated when we click on Install button within the VPM. Steps we are going to follow is to copy only the VPM-XML file of the first Edge SWG (ProxySG) to the second one. As VPM-CPL is generated every time the Install button is clicked, there is no need to copy this to the second Edge SWG (ProxySG).
Steps to replicate the VPM
Note: For ease of reference, the source Edge SWG (ProxySG) is termed as Proxy-1 and the destination as Proxy-2
Note-: It is important that the step-11 (Install in the VPM) is completed, for the policy to take effect on the Proxy-2
For the SGAC, the policy files can be accessed as shown in the snippets below.
Where there are any failures during the policy file restore, on another similar appliance, the failed piece would have to be manually reconfigured.