Policy Planning Reversion & Cleanup Scripts for SSP 5.2
search cancel

Policy Planning Reversion & Cleanup Scripts for SSP 5.2

book

Article ID: 449999

calendar_today

Updated On:

Products

VMware vDefend Firewall with Advanced Threat Prevention

Issue/Introduction

Customers who have published policies and inventory assets generated through Policy Planning on SSP may want to undo these publications. Simply discarding the analysis through SSP will not revert the publications made to NSX.

We provide 2 scripts:

  1. A script that identifies the groups, policies, rules, and tags published through an existing Policy Planning analysis and provides the option to selectively revert them (used before discarding the CSV).
  2. A script that identifies all groups that have been published through Policy Planning and deletes them on NSX, as well as removes all hierarchy tags from their effective VMs (used after discarding the CSV).

Environment

This script requires SSP 5.2. This script is not applicable to earlier versions of SSP.

Cause

If publications are made to NSX through Policy Planning, they will remain on NSX even if the "Reimport" button is used in Policy Planning to discard the current CSV. Publications that remain on NSX can include:

  • Hierarchy groups, such as Applications, Application tiers, and Environments.
  • Policies and Rules.
  • Tags that have been added to assets.
  • Tags that have been removed from assets.

Resolution

Please Contact Broadcom Support team to run this script.

Attachments

revert-planning-publications-5_2.py get_app
cleanup-segmentation-objects-5_2.py get_app