Hi
I have planned to integrate Identity Awareness for Large Scale with existing production firewall, we have existing 1700+ Rule with "networks, service object" So my target is Add "AD User, Networks, Service object on the top of existing rule with new rule for Monitoring before migrate to New Rule with Access role.
Example Existing Rule
Source IP have 20+ Object, Destination IP 20+ Object
If possible don't change behavior for my customer admin to manage their firewall. existing behavior admin can verify src,dst IP its just look at the rule because src,dst shown on the rule. In the feature admin have to double click on "access-role" for check src,dst IP some thing like that.
My English skill is not so good, But I'm try to explain!
GIAG R80.30