SegAudit
Trust center

Generated changes

Why the tool cannot change your firewall, and how its suggested changes are kept safe.

The tool writes change plans. It never applies them.

  • No write path. It does not connect to Panorama, FortiAnalyzer, ASDM or a firewall and has no commit capability.
  • Read-only export scripts. The optional evidence scripts only call the PAN-OS XML API’s keygen, configuration show and log retrieval. They never call set, edit, delete, commit or op. The password is prompted for, sent once in a POST body, and exchanged for an API key sent in a header. TLS is verified by default.
  • FortiGate export scripts. They sign in with a REST API token or a password, request the masked configuration backup and read the forward-traffic log. They never change a policy or setting. FortiOS only allows the backup to an admin profile with System read-write, so a read-only profile exports the log alone; the backup can then be taken from the web interface.
  • FortiGate changes in FortiOS. On FortiGate evidence the change package is written in FortiOS CLI, with a REST API script, web interface steps, read-only pre-checks, verification and rollback. Applied, verified and rolled back on FortiGate-VMs running FortiOS 7.4.12 and 8.0.1, each returning to its original configuration.
  • Cisco ASA changes in ASA CLI. On ASA evidence the change package, Remediation plan scripts and isolation runbook are written in ASA CLI, with pre-checks, packet-tracer verification and rollback, plus ASDM steps and an Ansible playbook for the change package. Collection needs no script: the engineer records show running-config from their own SSH session. Applied, verified and rolled back on ASAv 9.18 and 9.24.
  • Cisco FTD changes through FMC. FMC has no configuration CLI, so on FTD evidence each change is a Python script (standard library) that works through the FMC REST API: check is read-only, rollback restores from a copy taken before apply, and nothing reaches the FTDs until the policy is deployed. Each change also comes as FMC web steps and packet-tracer checks. Collection uses a read-only export script with an FMC user in the Security Analyst (Read Only) role. Checked on FMC and FTD 7.4.
  • Check Point changes through the Management API. On Check Point evidence each change is a Python script (standard library) that works through the Management API: check is read-only, rollback restores from a copy taken before apply, and nothing reaches the gateways until the policy is installed. Each change also comes as SmartConsole steps and fw up_execute checks. Collection uses a read-only export script with an administrator on the Read Only All profile. Checked on R82.
  • Safety gates. A change window is blocked if it would skip the snapshot, open a new path through an unused rule, leak plant addressing into a shared rule, or drop logging.
  • Built from evidence only. Exceptions keep what the evidence window saw. Each change’s risk assessment says so, pre-checks confirm the firewall still matches the evidence, and global changes go to a pilot plant first.
  • Rollback for everything. Every plan carries its rollback: re-enable, restore descriptions and tags, delete inserted drops.

Suggested CLI can disable production rules. Stage it in a lab or non-production device-group and follow your change advisory process.

Last updated 2026-10-02.