Flowcharting rules

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Flowcharting rules

L4 Transporter

It sounds as if my situation is a bit different than most as from what I gather most people do not use the scheduling feature of the firewall.  I am at a pre-K-12 boarding school with dorm students, dorm parents, etc. which means I use the scheduling piece in almost every rule!   As part of this I am struggling a bit of following the logic of my rule set (I pity the person who takes this it over of I leave!).

I am curious if anyone has been using some sort of third party mind mapping/flow charting software to draw out the logic of their rules?  I am not a big fan of Visio.

OR

Do people use the PA on it's own and just keep adding to it without mapping it out?

Thanks

Bob

10 REPLIES 10

Not applicable

PA on its own with rule comments, or a "simple" Excel spreadsheet with a couple macros and bonus fields :smileysilly:

L4 Transporter

That is one area that the PAs are really lacking. There are no visualization tools like Cisco ASAs and Netscalers, and no grouping of rules based on zones or policy type like the MS ISA. It also does not even have a numbering column, which is very strange!  It would be nice to see some of these introduced. We use the TAG field and the description field to try to keep track of things. There is also an API to export all of the rules to an excel spreadsheet which might be a help.

The inherent vice of capitalism is the unequal sharing of blessings; the inherent virtue of socialism is the equal sharing of miseries.

L4 Transporter

Here is the link to the user DOC on importing to Excel:

Here is the DOC on using the REST API for more info: -

The inherent vice of capitalism is the unequal sharing of blessings; the inherent virtue of socialism is the equal sharing of miseries.

L4 Transporter

For my sanity, I group the rules by zone. But, that was back when you could sort the rules by zone easily back in PAN-OS 2.0. :smileysilly: I'm starting to use the tags as we've grown to 500+ rules.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!