SegAudit
Free Quick check

See what your firewall rules allow.

Drop a PAN-OS XML export, a FortiOS backup, a Cisco ASA running config, an FMC export for Cisco FTD or a Check Point export. SegAudit reads it here, in your browser, and shows which rules open paths across the Purdue levels into your control network. Your config is never sent to us.

No config to hand?

  • Read in this tabThe file is parsed and analyzed by your browser, the same way the app does it. It is never uploaded.
  • Sending is blockedThis page's security policy (connect-src 'none') stops it making any network request. Open your browser's network panel and watch: nothing goes out.
  • Config onlyNo traffic log needed. The check shows what your rules allow; the full app shows which of those paths are actually used.
  • Up to 500 rulesLarger configs are checked on their first 500 rules, in rule order. The free Community edition reads the whole config.

How to export your config

Palo Alto PAN-OS or Panorama

Device → Setup → Operations → Export named configuration snapshot (on Panorama, Panorama → Setup → Operations), and pick running-config.xml. The XML API export works too.

Fortinet FortiGate

Configuration → Backup with Password mask on and Encryption off (FortiOS 7.4 and 7.6), or Mask sensitive information on FortiOS 8.0.

Cisco ASA

Over SSH, run terminal pager 0 then show running-config and save the session to a file, or use ASDM's Tools → Command Line Interface. The banner and prompts in the file are fine.

Cisco FTD (managed by FMC)

Run the read-only export script, segaudit-export-fmc.py (Python) or SegAudit-Export-FMC.ps1(PowerShell), with an FMC user in the Security Analyst (Read Only) role, and drop the export here.

Check Point

Run the read-only export script, segaudit-export-checkpoint.py (Python) or SegAudit-Export-CheckPoint.ps1(PowerShell), with an administrator on the Read Only All profile, and drop the export here.

More detail is in what to export. See the data flow for how the app handles files.