---
sourceDocument: Yokohama IT Operations Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/it-operations-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Firewall rule requests

# Firewall rule requests {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Use Service Catalog to request new firewall policies and rules.  
Figure 1. Firewall rule request workflow

## Request firewall rule {#ariaid-title2}

Request one or more firewall rules using Service Catalog to manage various IP addresses and enhance network security and accommodate evolving business requirements.

### Before you begin

Verify that the Firewall Audits and Reporting catalog is enabled.

Role required: firewall_admin

### About this task

You can request multiple firewall rule configurations in a single request. The system creates one parent firewall task with individual configuration tasks for each rule. Administrators initiate tasks, which are automatically directed to the risk team for assessment and approval. Following approval, firewall admins smoothly implement changes, all orchestrated through automated workflows.  
Note:  
Starting with version 1.12.0 of Firewall Audits and Reporting, all new firewall rule tasks are created in the Panorama-specific table and display the task type as Panorama. Open requests created before version 1.12.0 are read-only. To proceed with those requests, resubmit them using the current catalog form.

### Procedure

1. Navigate to AllService CatalogFirewall Rules.
2. Select Request Firewall Rule.  
   Figure 2. Request Firewall Rule
3. Enter the appropriate information for the following mandatory fields.

* Source IP address
* Destination IP address
* Assignment GroupMust have the sn_disco_firewall.firewall_user role.

* Approval GroupMust have the approver_user role.

{#request-new-firewall-rule__ul_ygn_crt_4lb}

4. Enter or select any details that is required.
5. **Optional:** To add additional rule configurations, select Add Rule Config and enter the details for each additional rule.  
   Each rule configuration you add creates a separate configuration task under the same parent firewall task. All configurations share the common fields such as Assignment Group and Approval Group.
6. Select Submit.  
   The system creates one parent firewall rule task with individual configuration tasks for each rule you specified.

### What to do next

To verify the new rule task, navigate to Rule RequestsRule Requests Task. Your request appears in the list with the task type set to Panorama. Open the parent task to view all individual rule configuration tasks.

## Approve firewall requests {#ariaid-title3}

Approval of firewall requests gives you controlled access and compliance. Members of
the approver group can review and approve firewall audits and new firewall
requests.

### Before you begin

Role required: Members of the specified approver group
approval_group specified in the rule task. The admin user can
edit the approvers list in the Rule Request Task.

### Procedure

1. Navigate to AllSelf ServiceMy Approvals.
2. Select the green checkmark to approve.

### Result

* The Assignment group works on the request and marks it as Close Complete.
* Once the assignment_group marks the request Close Complete, if the change request plugin is activated, a background sub-flow creates a change request.  
  Note:  
  The change request is created only if the rule task is Approved and in Close Complete state.

{#approve-firewall-requests__ul_ylv_hlt_vlb}  
The Firewall rule task security policy M2M corresponds to the related list Security policies in Rule task. Firewall administrators can add description or tag fields in a security policy on a Panorama device. They can also add firewall rule task numbers or change request numbers while creating or modifying security policies on Panorama. When the next discovery runs, the M2M table populates the mapping between:

* Firewall rule task and firewall security policy
* Firewall security policy and business service if the business service is provided during the Firewall rule task request
{#approve-firewall-requests__ul_b2c_qxv_31c}

*[\>]: and then


