From firewall files to a verified change.
Four steps, the same on every audit.Four steps, the same on every engagement.Four steps, the same at every plant, every quarter. Each one below is the real screen you will use, filled in with the built-in Northline sample plant.
Export the files
The firewall engineer exports the running config, and a traffic log if the firewall keeps one. The evidence request writes the steps for them, with their device names filled in.
- One request covers every firewall in scope
- Each file's sha256 is recorded as it lands
- A traffic log is optional; configs alone still audit
Done by the firewall engineerDone by your client's firewall engineerDone by your firewall engineer
- nl-edge-fw01 PAN-OS 11.1Running config and 7 days of traffic
- nl-core-fw02 PAN-OS 11.1Running config
- nl-cell-fw03 FortiGate 7.4Running config and a FortiAnalyzer export
Step-by-step export instructions for each firewall, with these device names filled in.
| Firewall | File | sha256 | |
|---|---|---|---|
| nl-edge-fw01 | Running configPAN-OS 11.1 | a41f 09c2 … | Recorded |
| nl-core-fw02 | Running configPAN-OS 11.1 | 77c0 e15b … | Recorded |
| nl-cell-fw03 | Running configFortiGate 7.4 | 0be9 41d7 … | Recorded |
| nl-edge-fw01 | Traffic log, 09-21 to 09-28CSV export | 9f3c a71e … | Recorded |
The evidence request on the left goes to the firewall engineer. Files land on the right as they arrive.The evidence request on the left goes to your client's firewall engineer. Files land on the right as they arrive.The evidence request on the left goes to your firewall engineer. Files land on the right as they arrive.
See what is really open
Every session that crosses a Purdue level it shouldn't is ranked by risk, with the rule that allowed it and the hosts behind it.
- Ranked by risk, highest first
- The Purdue crossing and the rule behind each one
- Sessions from the traffic log, when you have one
Read by whoever runs the auditRead by you, with your own wording where you disagreeRead by your plant or security engineer
| Severity | Finding | Crossing | Sessions |
|---|---|---|---|
| High | F-112 Jump hosts reach the Cell A controllers on any service | L3.5 → L1 | 2,792 |
| High | F-104 Business network reaches Level 2 on RDP | L4 → L2 | 418 |
| High | F-117 Cell B talks to Level 1 on any service | L2 → L1 | 1,031 |
| Medium | F-121 Vendor VPN reaches the DMZ unrestricted | L5 → L3.5 | 96 |
| Medium | F-108 ICMP from the business network to Level 1 | L4 → L1 | 12 |
| Low | F-125 Telnet to Level 1 allowed, no sessions | L3 → L1 | 0 |
Violations for the built-in Northline sample plant.
Ship a safe change window
Changes in a safe order, each with CLI, rollback and a change ticket.Changes in a safe order, each with CLI, rollback and a change ticket for your client's change process.Changes in a safe order, each with CLI, rollback and a ticket for your change board.
- Each change pictured before and after
- Firewall syntax, web steps and a rollback
- Changes that would stop production are flagged before handoff
Goes to whoever approves firewall changesGoes to your client, who decides on each changeReviewed by your change board
CHG-07 from the sample: three flows kept, the rest logged and dropped.
Prove it with the next log
Drop the next traffic window and every plan comes back Verified, Regressed, Not applied or No traffic.
- Verified, Regressed, Not applied or No traffic
- One result for every change in the window
- Shown per change, ready to hand overShown per change, ready for the clientShown per change, ready for your change record
The firewall engineer drops the next logYour client's firewall engineer drops the next logYour firewall engineer drops the next log
| CHG-03 | Remove unused RDP from Level 4 to Level 20 sessions on the removed path | VERIFIED |
| CHG-05 | Drop the Level 4 to Level 1 ICMP rule0 sessions on the removed path | VERIFIED |
| CHG-06 | Restrict historian replication to tcp/5450Rule 18 unchanged in the new config | Not applied |
| CHG-07 | Narrow the Level 3.5 jump host path to Cell A3 flows kept, 4 drops logged | VERIFIED |
| CHG-08 | Log and drop the legacy any-any in cell-bPolicy 12 reopened on 10-09 | Regressed |
| CHG-10 | Split the vendor remote-access rule by vendorNo vendor sessions in the window | No traffic |
The next traffic window, checked against every change.
What you need
Files the firewall already produces. SegAudit reads them as they are.
- A running config
- The Panorama or standalone PAN-OS configuration, a FortiGate configuration backup, a Cisco ASA running config, an FMC export for Cisco FTD, or a Check Point export.
- A traffic log
- The traffic log from the same period, when the firewall keeps one. One file per firewall is fine.
- A place to run it
- One signed container on a workstation or jump host. It works with no internet connection.
- A browser
- The analysis runs in the browser tab. Nothing is uploaded to the container or anywhere else.
What it never does
Built for networks where nothing may reach in or out.
- Never connects to a firewall
- No login, no API key, no firewall credential held.
- Never changes your config
- It writes the change. Your engineers review and apply it.
- Never uploads evidence
- Files are read in the browser and kept in memory until the tab closes.
- No account or telemetry
- No sign-in, no analytics, no update check.
Common questions
- Can I try it without our own files?
- Yes. SegAudit ships with the Northline sample plant, so you can follow every step before exporting anything.
- What if a zone is mapped wrong?
- Correct the mapping and the findings recompute.
- Can we pause and resume?
- Save the audit as a file, encrypted with a passphrase if you like. Load it later, or load next quarter's files into it to keep your checkpoints.
- What comes out at the end?
- An audit report, change package, executive brief and more, in Word and markdown, in one .zip with the evidence hashes. See the sample deliverable.
See it with your own files
The Community edition is free and opens the Northline sample, so every screen above is one download away.