Firewall optimizer

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Firewall optimizer

L4 Transporter

Any one out there using firemon or algosec to optimize your firewall? I am interested in your opinions whether you like it or not and which one is better or if there are other options

6 REPLIES 6

Cyber Elite
Cyber Elite

I've used firemon on the PA and on Cisco ASAs. It's a pretty cool product and it integrates with both pretty easily. I would say that it's actually easier to integrate with the PA than an ASA as you already have the API exposed on the PA, where on the ASA you actually have to load it in. Unless you are managing multiple firewalls I wouldn't really say that Firemon is needed with the PA though. A large amount of what Firemon is used for on a daily basis is already covered with built-in features. 

 

I know that they looked at algosec and decided against it but I'm not sure what was the actual reason, whether it was cost or feature set I'm not sure. 

I tried to do a algosec POC but they told me they wouldn't make enough money selling to me to make it worth their while. I did a firemon POC and it was pretty cool but it give soooo much information its hard to parse.

The good thing about firemon is that you can purchase what you actually need access to and cut down on most of that. I do find myself ignoring some of the features of firemon as unnecessary through. That may have been the reason why we didn't give algosec much attention, it's weird that they wouldn't have pricing for smaller establishments/installs though.  

So BPry you have firemon? I did like that you could buy just the features that you needed. What built in features do you use to find out which are the permissive rules and how to optimize them etc?

You would just want the policy optimizer if that is all you are looking to do. Just know that Firemon will essentially become your portal to the Palo Alto if you are using it 'correctly'. I would make sure that you lock down access to Firemon pretty tightly and make sure that the admins that have full access to it realize that changes that they make in Firemon can become live changes pretty easily. 

Thanks for the advice BPry, I am also going to do a proof of concept on tufin's firewall optimizer. Right now I am also seeing if the ACC can give me the information I need

  • 2137 Views
  • 6 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!