This section describes how to use the redundant policy analysis tool.
The redundant policy analysis tools identify redundant policies by analyzing all policy match conditions, including:
The device compares policies from the highest priority to the lowest priority. If a policy meets either of the following conditions, the policy is considered redundant.
Redundant policy analysis can be performed after security policies are configured, regardless of whether traffic is passing through the FW.
Default policies are not included in redundant policy analysis. Security profiles referenced in security policies are not analyzed. Only the match conditions and actions of security policies are analyzed.
As shown in the following figure, the policies and their redundant policies are displayed from the highest priority to the lowest priority.

Security policies are matched top down. The policy on the top has more significant implications than other policies. Therefore, verify the policies from the top down to the bottom. You can modify or delete redundant policies as needed.
of the policy.After a redundant policy is modified or deleted, the redundant policy analysis result automatically updates.