See what your firewall rules allow.
Drop a PAN-OS XML export, a FortiOS backup, a Cisco ASA running config, an FMC export for Cisco FTD or a Check Point export. SegAudit reads it here, in your browser, and shows which rules open paths across the Purdue levels into your control network. Your config is never sent to us.
- Read in this tabThe file is parsed and analyzed by your browser, the same way the app does it. It is never uploaded.
- Sending is blockedThis page's security policy (connect-src 'none') stops it making any network request. Open your browser's network panel and watch: nothing goes out.
- Config onlyNo traffic log needed. The check shows what your rules allow; the full app shows which of those paths are actually used.
- Up to 500 rulesLarger configs are checked on their first 500 rules, in rule order. The free Community edition reads the whole config.
Your scorecard
Paths to look at first
Fix these, export the config again and re-run the check. This browser remembers the counts (never the file), so you can see the number come down.
More findings in the full report
What a full audit adds to this config
Every plant, every quarter
Plant edition audits all your firewalls with traffic evidence and shows progress from one quarter to the next. $2,000 per plant per year, minimum 2 plants.
Turn this into a client deliverable
Professional writes the report, change plan and readout under your firm's letterhead, for every plant in the engagement. Try it on a real job before you buy.
Not ready yet? The free Community edition runs the full analysis on one plant, up to 2 firewalls; add a traffic log to see which paths are actually used. Or ask us about these results.
What that email contains
It opens in your own mail client so you can read it before sending. It holds the counts above and nothing else: no rule names, zones or addresses.
Check the Purdue levels Levels are guessed from zone names. Correct any that are wrong and the scorecard updates.
| Zone | Purdue level |
|---|
A Quick check reads rules only, so every finding is a path the config allows, not one seen in use. It is a starting point, not an audit. Check another config, which clears this one from the page.
How to export your config
Palo Alto PAN-OS or Panorama
Device → Setup → Operations → Export named configuration snapshot (on Panorama, Panorama → Setup → Operations), and pick running-config.xml. The XML API export works too.
Fortinet FortiGate
Configuration → Backup with Password mask on and Encryption off (FortiOS 7.4 and 7.6), or Mask sensitive information on FortiOS 8.0.
Cisco ASA
Over SSH, run terminal pager 0 then show running-config and save the session to a file, or use ASDM's Tools → Command Line Interface. The banner and prompts in the file are fine.
Cisco FTD (managed by FMC)
Run the read-only export script, segaudit-export-fmc.py (Python) or SegAudit-Export-FMC.ps1(PowerShell), with an FMC user in the Security Analyst (Read Only) role, and drop the export here.
Check Point
Run the read-only export script, segaudit-export-checkpoint.py (Python) or SegAudit-Export-CheckPoint.ps1(PowerShell), with an administrator on the Read Only All profile, and drop the export here.
More detail is in what to export. See the data flow for how the app handles files.