Firewall Analyzer

Firewall rule review for Cisco, Palo Alto and FortiGate

Find the firewall rules that never fire.

Paste an ASA running-config, a Palo Alto XML export, a FortiGate backup or an FMC export. In seconds you get the shadowed and redundant rules, any-any exposure, unused objects and every change since your approved baseline — the review you otherwise do in a spreadsheet the week before an audit.

Open the analyzer Free during early access. No sign-up. Opens with a sample loaded.
From the sample report
2access-list outside_in extended permit tcp any object-group WEB-SERVERS object-group WEB-PORTS log 5access-list outside_in extended deny tcp any host web-02 eq www
highRule is shadowed - it can never matchFW-010

Line 5 (deny) never matches: all of its traffic is taken first by line 2, which permits it. WEB-PORTS includes www and WEB-SERVERS includes web-02, so the intended block has never applied.

Remediation. Decide which behaviour is intended: move the deny above line 2, or delete it.

Privacy

Your configuration never leaves your browser.

A firewall config is a map of your network. The analyzer runs entirely on your computer: nothing you paste or drop is sent to us or anyone else, and nothing is stored after you close the tab.

You don't have to take our word for it. Every page is served with a security policy that forbids it from making network requests at all, so it could not upload your config even if it tried. Check the Content-Security-Policy response header in your browser's developer tools:

connect-src 'none'
form-action 'none'
script-src 'self'
default-src 'none'

What it checks

The questions an auditor asks, answered from the config.

Rule order

  • Shadowed rules that an earlier rule with a different action always pre-empts.
  • Redundant rules whose traffic earlier rules already handle the same way.
  • Decided by exact set arithmetic over zones, IPv4/IPv6 addresses and ports, including rules covered only by a combination of earlier rules. Never guessed.

Exposure

  • Any-any rules, rules open on every port, any source or any destination.
  • RDP, SSH, SMB, Telnet, SNMP, databases and other admin or cleartext services reachable from anywhere.
  • Unusually broad networks, broad Trust rules, permissive default actions, ASA interfaces with no inbound access list, and FortiGate admin access open on the WAN.

Hygiene and objects

  • Rules with zero hits or no hits in 180 days, from ASA or FMC hit counters.
  • Logging disabled, no intrusion policy, no comment or justification, disabled rules.
  • Unused objects, objects used only by disabled rules, and duplicates holding the same value.

Drift from baseline

  • Rules added, removed, changed or moved since the last approved config.
  • Object values that changed underneath every rule that uses them.
  • Each finding carries related PCI DSS v4.0, NIST 800-53 and CIS v8 references for the reviewer.

Platforms

Bring the config you already have.

Cisco ASA

Two read-only commands. Paste both into the analyzer, one after the other.

terminal pager 0
show running-config
show access-list

The second gives hit counters. Every access list bound with access-group is audited, each as its own chain.

Cisco Secure Firewall (FMC, cdFMC)

An export of the access policy from the FMC REST API: the access rules, the object inventory and, optionally, hit counts. Drop the JSON files together; they are merged.

A read-only collector that pulls this for you is part of the command-line edition.

Palo Alto Networks (PAN-OS, Panorama)

The XML configuration: Device > Setup > Operations > Export named configuration snapshot, or from the CLI:

set cli config-output-format xml
show config running

Every vsys is audited as its own rulebase; for Panorama, each device group with its shared and local pre- and post-rules.

Fortinet FortiGate

The configuration backup: admin menu > Configuration > Backup, or from the CLI:

show full-configuration

Policies are checked in the order they appear, which is how FortiOS evaluates them. Each VDOM is its own rulebase.

Any other firewall

A spreadsheet export with one rule per row works too: name, action, zones, source, destination, services, and optionally log, hits and comment.

Values can be CIDRs, ranges, tcp/443-style services, or any.

See it on a sample first.

The analyzer opens with a fictional ASA already loaded, problems planted on purpose, so you can see every kind of finding before pasting your own.

Open the analyzer