I am starting to work on Threat Prevention in an environment with many years of history updating the SMS and Gateways from R77 to R80+. Everything is now R80+.
There is several Threat Prevention profiles cloned from Optimized applied to the shared IPS layers as well as Threat Prevention under Custom Policy. I can't risk making potentially large scale changes, and need to take a step back and work with a single gateway and "clean" Optimized profile.
I believe the profiles currently in use were cloned AFTER changes to the default Optimized profile. Many IPS Protections were changed from the default action for the Optimized profile, General Policy settings for the profile were changed in various ways and changed back, IPS Updates exceptions, etc. I've spent days looking at this and it's next to impossible to make sense of it, and even more daunting to think about making changes without breaking all the things.
I want to run the "profile cleanup" action to start with a clean/baseline clone of the default Optimized profile. It's not practical to run this against the current Optimized profile because that is assigned to several gateways and too big of blast radius. If I clone Optimized again and cleanup the cloned profile, will it reset to the default Optimized settings, IPS Protection activations, etc., or will it only reset to the point in time it was cloned?
If this works, I plan incremental steps to create similar clones of Optimized for each gateway and migrate from the shared IPS layer to Threat Prevention for specific Protected Scopes assigned to the cloned profiles.
Thanks!