Security Operations

Firewall Management

Full control over your rule base – documented and auditable

Firewall rule bases that grow over years quickly become opaque – and every undocumented rule is a security risk. Firewall management documents each rule with source, destination, port and protocol, links it to processes and assets, and captures the live state of your devices automatically via the isidaten agent. A target-actual comparison reveals deviations, shadow and redundant rules at a glance – and keeps you in full control.

ISO 27001NIS2
Features

Your benefits

1

Your rule base in plain sight

Every rule with source, destination, port, protocol and action is cleanly documented and linked to processes and assets – including network zones and a zone matrix.

2

Automated target-actual comparison

The isidaten agent captures the live state of your devices from FortiGate to Palo Alto, Check Point, Cisco, Sophos and UniFi – and surfaces deviations from the documented target state.

3

Expose shadow & redundant rules

Rule base analysis automatically finds shadowed, redundant and obsolete rules – you clean up, close gaps and reduce your attack surface.

4

Review & compliance evidence

Structured review workflows, compliance reports and a complete change history provide proof that your rule base is reviewed regularly.

Capabilities

Everything this module can do

  • Document rules: source, destination, port, protocol, action
  • Link rules to processes and assets
  • Network zones including zone matrix
  • SNI/hostname-to-IP mappings
  • Live state capture via isidaten agent
  • Devices: FortiGate, Palo Alto, Check Point, Cisco FMC
  • Also Sophos, UniFi, WatchGuard & host firewalls
  • Automated target-actual comparison
  • Rule base analysis: shadow, redundancy, correlation
  • Review workflow, compliance report, change history

Experience Firewall Management live

Schedule a no-obligation demo – we will show you the module with your own use cases.