07-08-2021 05:36 AM
Looking for software that can report if one object in a rule is unused.
example: I have 3 destination IP's in one rule, but one might not be receiving any hits.
I recall a Consultant ran a software package during a firewall audit that could do this.
We had to configure the Firewall tp send Syslog to this package.
This package also had an admin ID on the firewall so it could download new policy.
This package performed full time audit to see what objects were not being used. It probably did other things like make recommendations on firewall policy order, etc.
but I can't find the name of that package now :(.
thanks
08-24-2021 06:07 AM - edited 08-24-2021 06:14 AM
It looks like Firemon can do it. I have never used it because it is pricey.
https://www.firemon.com/detox-step-2-remove-unused-access/
"it is possible to identify most used rules, which objects are used in a rule"
Algosec also makes a similar expensive tool. So does Tufin. You would have to research the features. Google "firewall nspm".
08-24-2021 07:04 AM
Thanks Tom. I have been in touch with Firemon and it sounds like a great product.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!