If someone makes a policy change, then cant push policy.
And you go to policies/installation history and push the last known good policy - and it works!
The policy that exists on the management server is still the bad one right?
How do you revert the one on the management server to the last known good version? Do you need to do a database revision under manage&settings/Sessions/Revisions?
This would blatt all the objects created since that revision right?
In some cases we have customers with hundreds of gateways and multiple admins making concurrent changes all the time - a db revision is not feasible to fix one smb.
I found this SK to revert to the version on the gateway which is interesting - but again - this would make the policy on the mgmt server out of sync right? At least you can see the current revision number with this tool but how to correlate that to the mgmt server? The revision number isnt listed under revisions or installation history (as far as I can see);
sk181437 - Access Control Policy Revert Tool (policy_rev_tool)
[Expert@GW1:0]# policy_rev_tool list
Revision ID Policy Date Policy Name
----------- ----------- -----------
1760977277 Mon Oct 20 17:21:17 BST 2025 all_gateways_policy
1760977421 Mon Oct 20 17:23:41 BST 2025 all_gateways_policy
1760977922 [c] Mon Oct 20 17:32:02 BST 2025 all_gateways_policy
[c] - current policy
The manual is 'light' on the implications
"To work with the Policy installation history:
In SmartConsole
, go to Security Policies.From the Access Tools or the Threat Prevention Tools, select Installation History.
In the Gateways section, select a Security Gateway.
In the Policy Installation History section, select an installation date.
Perform the applicable action:
To see the revisions that were installed and who made them:
Click View installed changes.
To see the changes that were installed and who made them :
Click View.
To revert to a specific version of the policy:
Click Install specific version."
Thanks