Looking for audit software that can show if one object is not used in FW rule.

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Looking for audit software that can show if one object is not used in FW rule.

L0 Member

Looking for software that can report if one object in a rule is unused. 

example: I have 3 destination IP's in one rule, but one might not be receiving any hits.

 

I recall a Consultant ran a software package during a firewall audit that could do this.

We had to configure the Firewall tp send Syslog to this package. 

This package also had an admin ID on the firewall so it could download new policy.

This package performed full time audit to see what objects were not being used.  It probably did other things like make recommendations on firewall policy order, etc.

but I can't find the name of that package now :(.

thanks

2 REPLIES 2

Cyber Elite
Cyber Elite

It looks like Firemon can do it.  I have never used it because it is pricey.

 

https://www.firemon.com/detox-step-2-remove-unused-access/

 

"it is possible to identify most used rules, which objects are used in a rule"

 

Algosec also makes a similar expensive tool.  So does Tufin.  You would have to research the features.  Google "firewall nspm".

Help the community: Like helpful comments and mark solutions.

L0 Member

Thanks Tom.  I have been in touch with Firemon and it sounds like a great product. 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!