SegAudit
How it works

From firewall files to a verified change.

Four steps, the same on every audit.Four steps, the same on every engagement.Four steps, the same at every plant, every quarter. Each one below is the real screen you will use, filled in with the built-in Northline sample plant.

1

Export the files

The firewall engineer exports the running config, and a traffic log if the firewall keeps one. The evidence request writes the steps for them, with their device names filled in.

  • One request covers every firewall in scope
  • Each file's sha256 is recorded as it lands
  • A traffic log is optional; configs alone still audit

Done by the firewall engineerDone by your client's firewall engineerDone by your firewall engineer

Evidence request
Evidence request · Northline (sample plant)Files for the October audit
  1. nl-edge-fw01 PAN-OS 11.1Running config and 7 days of traffic
  2. nl-core-fw02 PAN-OS 11.1Running config
  3. nl-cell-fw03 FortiGate 7.4Running config and a FortiAnalyzer export

Step-by-step export instructions for each firewall, with these device names filled in.

Evidence · 5 files
FirewallFilesha256
nl-edge-fw01Running configPAN-OS 11.1a41f 09c2 …Recorded
nl-core-fw02Running configPAN-OS 11.177c0 e15b …Recorded
nl-cell-fw03Running configFortiGate 7.40be9 41d7 …Recorded
nl-edge-fw01Traffic log, 09-21 to 09-28CSV export9f3c a71e …Recorded

The evidence request on the left goes to the firewall engineer. Files land on the right as they arrive.The evidence request on the left goes to your client's firewall engineer. Files land on the right as they arrive.The evidence request on the left goes to your firewall engineer. Files land on the right as they arrive.

2

See what is really open

Every session that crosses a Purdue level it shouldn't is ranked by risk, with the rule that allowed it and the hosts behind it.

  • Ranked by risk, highest first
  • The Purdue crossing and the rule behind each one
  • Sessions from the traffic log, when you have one

Read by whoever runs the auditRead by you, with your own wording where you disagreeRead by your plant or security engineer

Violations · 31
SeverityFindingCrossingSessions
HighF-112 Jump hosts reach the Cell A controllers on any serviceL3.5 → L12,792
HighF-104 Business network reaches Level 2 on RDPL4 → L2418
HighF-117 Cell B talks to Level 1 on any serviceL2 → L11,031
MediumF-121 Vendor VPN reaches the DMZ unrestrictedL5 → L3.596
MediumF-108 ICMP from the business network to Level 1L4 → L112
LowF-125 Telnet to Level 1 allowed, no sessionsL3 → L10

Violations for the built-in Northline sample plant.

3

Ship a safe change window

Changes in a safe order, each with CLI, rollback and a change ticket.Changes in a safe order, each with CLI, rollback and a change ticket for your client's change process.Changes in a safe order, each with CLI, rollback and a ticket for your change board.

  • Each change pictured before and after
  • Firewall syntax, web steps and a rollback
  • Changes that would stop production are flagged before handoff

Goes to whoever approves firewall changesGoes to your client, who decides on each changeReviewed by your change board

Change package · CHG-07
Level 4EnterpriseLevel 3.5DMZLevel 3OperationsLevel 2SupervisoryLevel 1ControlRule 14 reaches every Level 1 asset, on any servicenl-edge-fw01jump-hostsplc-a-01modbusplc-a-02modbushmi-a-01ethernet-ipeng-sharesmblogged anddropped+14 moreskips Level 3 and Level 2
Kept, narrowed to what was usedWhat rule 14 allowedLogged and dropped

CHG-07 from the sample: three flows kept, the rest logged and dropped.

4

Prove it with the next log

Drop the next traffic window and every plan comes back Verified, Regressed, Not applied or No traffic.

  • Verified, Regressed, Not applied or No traffic
  • One result for every change in the window
  • Shown per change, ready to hand overShown per change, ready for the clientShown per change, ready for your change record

The firewall engineer drops the next logYour client's firewall engineer drops the next logYour firewall engineer drops the next log

Verify · traffic 10-05 to 10-12
CHG-03Remove unused RDP from Level 4 to Level 20 sessions on the removed pathVERIFIED
CHG-05Drop the Level 4 to Level 1 ICMP rule0 sessions on the removed pathVERIFIED
CHG-06Restrict historian replication to tcp/5450Rule 18 unchanged in the new configNot applied
CHG-07Narrow the Level 3.5 jump host path to Cell A3 flows kept, 4 drops loggedVERIFIED
CHG-08Log and drop the legacy any-any in cell-bPolicy 12 reopened on 10-09Regressed
CHG-10Split the vendor remote-access rule by vendorNo vendor sessions in the windowNo traffic

The next traffic window, checked against every change.

What you need

Files the firewall already produces. SegAudit reads them as they are.

A running config
The Panorama or standalone PAN-OS configuration, a FortiGate configuration backup, a Cisco ASA running config, an FMC export for Cisco FTD, or a Check Point export.
A traffic log
The traffic log from the same period, when the firewall keeps one. One file per firewall is fine.
A place to run it
One signed container on a workstation or jump host. It works with no internet connection.
A browser
The analysis runs in the browser tab. Nothing is uploaded to the container or anywhere else.

What it never does

Built for networks where nothing may reach in or out.

Never connects to a firewall
No login, no API key, no firewall credential held.
Never changes your config
It writes the change. Your engineers review and apply it.
Never uploads evidence
Files are read in the browser and kept in memory until the tab closes.
No account or telemetry
No sign-in, no analytics, no update check.

Common questions

Can I try it without our own files?
Yes. SegAudit ships with the Northline sample plant, so you can follow every step before exporting anything.
What if a zone is mapped wrong?
Correct the mapping and the findings recompute.
Can we pause and resume?
Save the audit as a file, encrypted with a passphrase if you like. Load it later, or load next quarter's files into it to keep your checkpoints.
What comes out at the end?
An audit report, change package, executive brief and more, in Word and markdown, in one .zip with the evidence hashes. See the sample deliverable.

See it with your own files

The Community edition is free and opens the Northline sample, so every screen above is one download away.

Download freeStart a 30-day trial