Palo Alto, Fortinet, Cisco and Check Point firewalls today.
SegAudit reads files your engineers already know how to export: a running config and, when you have one, a traffic log. It never logs in to a firewall or management server, and it never commits a change. This page lists what works today, what it needs from you and where its limits are.
Supported today
| Platform | Input | Status |
|---|---|---|
| Panorama-managed firewalls | Panorama running config (XML) and traffic log (CSV); device-groups, Shared, pre- and post-rules | Supported |
| Standalone PAN-OS firewalls | Firewall running config (XML) and traffic log (CSV) | Supported |
| Device-ID enrichment | PAN-OS 10.0 and later traffic logs with Device-ID or IoT Security on | Supported |
| Fortinet FortiGate | Masked full-configuration backup (.conf), single or multi-VDOM, and forward-traffic logs | Supported |
| Fortinet FortiAnalyzer | Forward-traffic logs downloaded as raw or CSV, with the FortiGate's configuration backup | Supported |
| Cisco ASA (ASA 9.x, including ISA 3000 and ASA 5500-X) | show running-config and the ASA's syslog (connection and deny messages) for the window, single-context mode | Supported |
| Cisco Secure Firewall Threat Defense (FTD), managed by Firewall Management Center (FMC) 7.4 | An FMC export from the read-only export script (Python or PowerShell) and the FTDs' connection-event syslog for the window | Supported |
| Check Point Security Gateways managed by a Security Management Server or Multi-Domain Server, R81.10 to R82 | A Check Point export from the read-only export script (Python or PowerShell) and the gateways' firewall logs for the window | Supported |
Tested end to end on PAN-OS 11.2, FortiOS 7.4.12, 7.6.7 and 8.0.1, ASA 9.18 and 9.24, FMC and FTD 7.4, and Check Point R82. To confirm yours before you buy, run the free Quick check on your own config, or the free Community edition on one firewall.
What we need from the firewall
The configuration, and a traffic log from the same period when you have one. A configuration alone gives results marked not verified by traffic; the log adds proof of what is actually in use. The evidence request in the app writes the instructions for your engineer, with device names and dates filled in.
Export the configuration
The Panorama or firewall running config, a FortiGate configuration backup with passwords masked, an ASA's show running-config, for FTD an FMC export, or for Check Point a Check Point export, from the read-only scripts. A Panorama config is preferred when Panorama manages the plants.
Export the traffic log for the same period
From the firewall, Panorama or FortiAnalyzer, by web interface, CLI or the export scripts, for an ASA or FTD from the syslog server that receives its logs, or for Check Point from the export script or Log Exporter's syslog server. One file per firewall is fine; they are merged on load.
Pick a long enough window
A week shows what is in use. Ask for 30 days or more when the work will retire rules that look unused, so rare flows show up.
Send both files and their SHA-256
The scripts print the hashes. SegAudit shows the same hashes on Review, in the audit report and in the deliverables pack.
Read-only collection
Optional export scripts, in Python and PowerShell, collect both files for PAN-OS and for FortiGate, and the FMC export script, in Python and PowerShell too, collects the policy for Cisco FTD. The Check Point export script, in Python and PowerShell, collects both files for Check Point. For a Cisco ASA, the evidence request has your engineer record an SSH session of show running-config and export the syslog. The scripts read configuration and logs only, never change a policy or commit, and print each file's SHA-256. The password is prompted for and never written to disk.
Plants from device-groups and VDOMs
Panorama device-groups, FortiGate VDOMs, each ASA, each FMC access control policy and each Check Point policy package become plants, so a multi-site estate is reviewed plant by plant.
Sessions meet their rules
Every logged session is matched to the rule that allowed it, on every supported firewall, so findings show the evidence behind them.
Change plans per plant
When rule names repeat across plants, plans are written per plant, and global changes go to a pilot plant first.
FortiGate change commands
The change package and isolation runbook come as FortiOS 7.4 to 8.0 CLI, a REST API script and web interface steps, with pre-checks, verification and rollback, on single- and multi-VDOM FortiGates. Applied, verified and rolled back on FortiOS 7.4.12 and 8.0.1.
Cisco ASA change commands
The change package and isolation runbook come as ASA CLI with pre-checks, packet-tracer verification and rollback, plus ASDM steps and an Ansible playbook. Applied, verified and rolled back on ASAv 9.18 and 9.24.
Cisco FTD change scripts
FMC has no configuration CLI, so each change comes as a script that works through the FMC REST API, with a read-only check, apply, rollback and deploy, plus FMC web steps and packet-tracer checks. Checked on FMC and FTD 7.4.
Check Point change scripts
Each change comes as a script that works through the Management API, with a read-only check, apply, rollback and policy install, plus pictured SmartConsole steps and fw up_execute checks. The isolation runbook comes the same way. Applied, installed and rolled back on R82.
The admin roles the scripts need, and exactly how each platform's files are read, are in the customer guides.
Known limits
Files over these caps are rejected before parsing. A CSV over the row cap is truncated with a warning. Filter the log window, or review plants separately, if you reach one.
| File | Size cap | Structure cap |
|---|---|---|
| Configuration (XML, .conf, FMC or Check Point export) | 32 MB | 250,000 elements, 20,000 security rules |
| Traffic log (CSV, FortiOS log, ASA or FTD syslog, Check Point log) | 64 MB | 250,000 session rows across all logs together |
| Saved engagement (JSON) | 96 MB | Same rule and row caps |
The analysis is only as complete as the traffic log. SegAudit lists what the evidence cannot see on Review and in the report's scope notes:
- A short windowRules that look unused over a week may carry a month-end job. The report lists them as a blind spot.
- Allowed sessions onlyAn export without denied sessions hides what the firewall is already blocking.
- Rules that do not log at session endTheir traffic is missing from the evidence, so the analysis cannot judge them.
- A plant or firewall that sent no logsIt is named on Review so you can ask for its export.
- Sessions without User-ID, assets without Device-IDThe analysis still runs, with less detail on who and what.
Coming next
SegAudit supports Palo Alto Networks, Fortinet, Cisco ASA, Cisco FTD (FMC) and Check Point today. Other vendors and Strata Cloud Manager are not supported yet; this is the order they come in, with no committed dates.
| Platform or feature | Today | Outlook |
|---|---|---|
| FortiManager policy packages | Not yet | Planned FortiGate change plans as FortiManager policy packages. No release date yet. |
| Palo Alto Networks Strata Cloud Manager | Not yet | Planned Planned as Panorama gives way to it. Tell us if your plants are managed from it. |
| Cisco FTD managed locally by device manager (FDM) | Not yet | On demand. FTD managed by FMC is supported today. |
| Check Point Smart-1 Cloud and locally managed Quantum Spark gateways | Not yet | On demand. Check Point with a Security Management Server is supported today. |
Questions about compatibility
Does it need API access to the firewall?
No. SegAudit reads exported files and never logs in to a firewall, Panorama or FortiAnalyzer. The optional export scripts use the PAN-OS XML API, the FortiOS REST API, the FMC REST API or the Check Point Management API with a read-only user, run by your engineer. For an ASA, your engineer records an SSH session of show running-config.
Do we have to change anything on the firewall?
No. The web interface caps a CSV export at 65,535 rows by default. Raising that limit is a Panorama management setting; if your change process covers it, use the scripts instead. On a FortiGate, logging every session on the policies that touch OT gives complete evidence. On an ASA, logging at informational level or higher records allowed connections. On FTD, allow rules should log at the end of the connection and block rules at the beginning, to syslog. On Check Point, the rules that touch OT should have Track set to Log.
Which versions work?
Tested end to end on PAN-OS 11.2, on FortiOS 7.4.12, 7.6.7 and 8.0.1 in our FortiGate lab, on ASAv 9.18 and 9.24 in our ASA lab, on FMC and FTD 7.4 in our FTD lab, and on Check Point R82 in our Check Point lab; the Check Point export script is written for R81.10 to R82. Run the free Quick check on your own config, or the free Community edition on one firewall, to confirm before you buy.
Does it push changes?
No. There is no commit path. Change plans are text and scripts that your engineer reviews and applies through your own change process; for FTD and Check Point, your engineer runs the change script.