Cisco ASA
Two read-only commands. Paste both into the analyzer, one after the other.
terminal pager 0
show running-config
show access-list
The second gives hit counters. Every access list bound with access-group is audited, each as its own chain.
Cisco Secure Firewall (FMC, cdFMC)
An export of the access policy from the FMC REST API: the access rules, the object inventory and,
optionally, hit counts. Drop the JSON files together; they are merged.
A read-only collector that pulls this for you is part of the command-line edition.
Palo Alto Networks (PAN-OS, Panorama)
The XML configuration: Device > Setup > Operations > Export named configuration snapshot, or from the CLI:
set cli config-output-format xml
show config running
Every vsys is audited as its own rulebase; for Panorama, each device group with its shared and local pre- and post-rules.
Fortinet FortiGate
The configuration backup: admin menu > Configuration > Backup, or from the CLI:
show full-configuration
Policies are checked in the order they appear, which is how FortiOS evaluates them. Each VDOM is its own rulebase.
Any other firewall
A spreadsheet export with one rule per row works too: name, action, zones, source, destination,
services, and optionally log, hits and comment.
Values can be CIDRs, ranges, tcp/443-style services, or any.