- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
12-04-2015 06:40 AM
Anyone know of any good firewall optimization software for PA. One that can review the rules and make good suggestion to improve the rule order, removal etc?
12-04-2015 08:28 AM
I assume firemon has a price, anyone know of an open source version as well to look at?
12-07-2015 02:01 PM
I was in the same boat as you are; inherited about 850 lines of sec policies being migrated from other vendor's solution. My apporach to clean/optimize was to enable "Hightlight unused rules" and after a month i started disabling unused rules. Waited another month, documented disabled rules and scheduled rule removeal. And four more weekends like that. It took me about 2 months to reduce number of rules from 850 to 200. In the same time this excersise allowed me to get better understanding of the infrastructure. Out of all those disabled rules, i had 10 rules thate were required to put back; some legacy traffic users were not aware of.
You might be able to use PAN migration tool to upload firewall config and see if any duplication is showing.
12-08-2015 07:40 AM
Well the migration was complete a couple of months ago and I have been using the method that you mentioned but I was also told there is software out there that would be able to do some of that work for me. So I just thought I would see waht people are using and how they like it. So far the only suggestion I have had is firemon, I am probably going to download a trial of that and see what it does, but would love more suggestions
12-08-2015 01:20 PM
If you dont mind, once you downlaod and test software could you post your findings?
12-08-2015 02:08 PM
I can try it may not be something that can easlily be posted verbatim and it may take quite some time to complete the testing
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!