Glossary
One line each, in alphabetical order. Where there is more to a term than one line holds, the definition links to the page that covers it.
| Term | What it means |
|---|---|
| account | One connection to one system: an AWS account, an Azure subscription, a Panorama, a ServiceNow instance. Set up under Settings > Accounts. See Projects and accounts. |
| action | In Decommission, a saved set of criteria that identifies decommissioned assets, plus the destination they're exported to. See Actions. |
| attribute shortcut | A raw attribute path saved on an account so it can be added to a Group or Decommission action's criteria with one click. See Attribute shortcuts. |
| Automatic | The update type of a Group or action that applies changes on its own. Compare Manual. See Automatic and Manual. |
| Boundary | A rule about firewall rules: a statement describing the change requests it applies to, and a result of Pass, Fail, or Score & Review. See Boundaries. |
| candidate | In Decommission, an inventory item an action has identified as decommissioned, awaiting or past a decision. See Candidates. |
| change request | A description of a firewall change someone wants: one or more rules, each with an action, sources, destinations, and services. See Change requests. |
| client ID | The identifier of your Connect organization, shown under Settings > About and used in dynamic list URLs. |
| Connector | The optional on-prem agent that reaches systems inside your network: Panorama, NSX Manager, and Infoblox. See Connector. |
| criteria | The rules under Group Candidates or Decom Candidates that select which inventory items a Group or action matches. See Criteria. |
| discovery | A read-only run that brings a system's assets into Inventory. Runs when an account is provisioned and daily after that. See How Connect collects data. |
| dynamic list | The HTTPS URL at which a Group is published for firewalls to fetch, in Palo Alto (EDL), Check Point, and Fortinet formats. See Dynamic lists. |
| EDL | External Dynamic List, Palo Alto's name for a list a firewall fetches from a URL. Connect's Groups Accessed by EDL tab uses the term for every dynamic list format. |
| Enforced | The switch on a Boundary that includes it in evaluations. An unenforced Boundary is kept but ignored. See Boundary details. |
| environment | The Production, Staging, Development, or Testing/QA label on an account, available as a filter. |
| export | Anything Connect pushes out: a Group to an enforcement point, a change request to Guardicore or ServiceNow, a decommissioned asset to ServiceNow. See How Connect collects data. |
| Group | A named set of IP addresses maintained from criteria over Inventory, used in exports, dynamic lists, and Boundaries. See Groups. |
| Group Credentials | The shared username and password firewalls use to fetch dynamic lists, set under Settings > Group Credentials. See Dynamic lists. |
| inventory item | One discovered resource, with its addresses, tags, account, region, and raw attributes. See Inventory. |
| job | One unit of work the Connector performs: a Sync Group export or a Discover Inventory run, listed under Settings > Connectors > Jobs. See Watching jobs. |
| Manual | The update type of a Group or action that holds changes for a person to approve. Compare Automatic. See Automatic and Manual. |
| member | An inventory item that matches a Group's criteria. Its addresses are part of the Group's IPs. |
| nested Group | A Group included inside another, contributing its IPs regardless of the parent's criteria. See Nested Groups. |
| pending change | On a Manual Group, an addition or removal waiting for approval. See Automatic and Manual. |
| project | A folder in the tree that holds accounts, Groups, Boundaries, change requests, and actions, and that roles are granted on. See Projects. |
| provision | Supplying an account's credentials on its Provision page, after which its first discovery starts. See Integrations. |
| registration code | A single-use, 24-hour code from Settings > Connectors that pairs a Connector with your organization. See Installation. |
| result | A Boundary's verdict for the requests it matches: Pass, Fail, or Score & Review. See Boundaries. |
| role | A fixed set of permissions granted to a user on a project: Administrators, Project Managers, Readonly Users, Connect Boundary Author, Firewall Change Requestors, or Firewall Change Approvers. See Roles. |
| rule | One line of a change request: an action (Allow or Deny), sources, destinations, and services, with optional context. See Change requests. |
| score | The 0 to 100 value a Score & Review Boundary assigns to requests it matches; when no Pass or Fail Boundary matched, a request carries the highest score among its matches. See Boundaries. |
| state | Where a change request stands: Pending, Pass, Fail, Review, or Error. See Change requests. |
| statement | The part of a Boundary that describes which requests it applies to. See The statement. |
| target | An account a Boundary exports matching requests to, or an account a Group is exported to. See Boundary details and Exporting a Group. |
| vendor | The system an inventory item came from (AWS, Azure, Illumio, Infoblox, and so on), available as a filter. |