Looking for audit software that can show if one object is not used in FW rule.

Looking for software that can report if one object in a rule is unused. 

example: I have 3 destination IP's in one rule, but one might not be receiving any hits.


I recall a Consultant ran a software package during a firewall audit that could do this.

We had to configure the Firewall tp send Syslog to this package. 

This package also had an admin ID on the firewall so it could download new policy.

This package performed full time audit to see what objects were not being used.  It probably did other things like make recommendations on firewall policy order, etc.

but I can't find the name of that package now :(.


