Skip to main content

Glossary

One line each, in alphabetical order. Where there is more to a term than one line holds, the definition links to the page that covers it.

TermWhat it means
accountOne connection to one system: an AWS account, an Azure subscription, a Panorama, a ServiceNow instance. Set up under Settings > Accounts. See Projects and accounts.
actionIn Decommission, a saved set of criteria that identifies decommissioned assets, plus the destination they're exported to. See Actions.
attribute shortcutA raw attribute path saved on an account so it can be added to a Group or Decommission action's criteria with one click. See Attribute shortcuts.
AutomaticThe update type of a Group or action that applies changes on its own. Compare Manual. See Automatic and Manual.
BoundaryA rule about firewall rules: a statement describing the change requests it applies to, and a result of Pass, Fail, or Score & Review. See Boundaries.
candidateIn Decommission, an inventory item an action has identified as decommissioned, awaiting or past a decision. See Candidates.
change requestA description of a firewall change someone wants: one or more rules, each with an action, sources, destinations, and services. See Change requests.
client IDThe identifier of your Connect organization, shown under Settings > About and used in dynamic list URLs.
ConnectorThe optional on-prem agent that reaches systems inside your network: Panorama, NSX Manager, and Infoblox. See Connector.
criteriaThe rules under Group Candidates or Decom Candidates that select which inventory items a Group or action matches. See Criteria.
discoveryA read-only run that brings a system's assets into Inventory. Runs when an account is provisioned and daily after that. See How Connect collects data.
dynamic listThe HTTPS URL at which a Group is published for firewalls to fetch, in Palo Alto (EDL), Check Point, and Fortinet formats. See Dynamic lists.
EDLExternal Dynamic List, Palo Alto's name for a list a firewall fetches from a URL. Connect's Groups Accessed by EDL tab uses the term for every dynamic list format.
EnforcedThe switch on a Boundary that includes it in evaluations. An unenforced Boundary is kept but ignored. See Boundary details.
environmentThe Production, Staging, Development, or Testing/QA label on an account, available as a filter.
exportAnything Connect pushes out: a Group to an enforcement point, a change request to Guardicore or ServiceNow, a decommissioned asset to ServiceNow. See How Connect collects data.
GroupA named set of IP addresses maintained from criteria over Inventory, used in exports, dynamic lists, and Boundaries. See Groups.
Group CredentialsThe shared username and password firewalls use to fetch dynamic lists, set under Settings > Group Credentials. See Dynamic lists.
inventory itemOne discovered resource, with its addresses, tags, account, region, and raw attributes. See Inventory.
jobOne unit of work the Connector performs: a Sync Group export or a Discover Inventory run, listed under Settings > Connectors > Jobs. See Watching jobs.
ManualThe update type of a Group or action that holds changes for a person to approve. Compare Automatic. See Automatic and Manual.
memberAn inventory item that matches a Group's criteria. Its addresses are part of the Group's IPs.
nested GroupA Group included inside another, contributing its IPs regardless of the parent's criteria. See Nested Groups.
pending changeOn a Manual Group, an addition or removal waiting for approval. See Automatic and Manual.
projectA folder in the tree that holds accounts, Groups, Boundaries, change requests, and actions, and that roles are granted on. See Projects.
provisionSupplying an account's credentials on its Provision page, after which its first discovery starts. See Integrations.
registration codeA single-use, 24-hour code from Settings > Connectors that pairs a Connector with your organization. See Installation.
resultA Boundary's verdict for the requests it matches: Pass, Fail, or Score & Review. See Boundaries.
roleA fixed set of permissions granted to a user on a project: Administrators, Project Managers, Readonly Users, Connect Boundary Author, Firewall Change Requestors, or Firewall Change Approvers. See Roles.
ruleOne line of a change request: an action (Allow or Deny), sources, destinations, and services, with optional context. See Change requests.
scoreThe 0 to 100 value a Score & Review Boundary assigns to requests it matches; when no Pass or Fail Boundary matched, a request carries the highest score among its matches. See Boundaries.
stateWhere a change request stands: Pending, Pass, Fail, Review, or Error. See Change requests.
statementThe part of a Boundary that describes which requests it applies to. See The statement.
targetAn account a Boundary exports matching requests to, or an account a Group is exported to. See Boundary details and Exporting a Group.
vendorThe system an inventory item came from (AWS, Azure, Illumio, Infoblox, and so on), available as a filter.