<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firewall analizer for Policy Optimization and Cleanup in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firewall-analizer-for-policy-optimization-and-cleanup/m-p/3393674#M489244</link>
    <description>&lt;P&gt;It's bad form trolling a 6 year old post with links to your company's site.&lt;/P&gt;</description>
    <pubDate>Mon, 04 Jun 2018 14:13:51 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2018-06-04T14:13:51Z</dc:date>
    <item>
      <title>Firewall analizer for Policy Optimization and Cleanup</title>
      <link>https://community.cisco.com/t5/network-security/firewall-analizer-for-policy-optimization-and-cleanup/m-p/1862462#M489234</link>
      <description>&lt;H3&gt;Hi there,&lt;/H3&gt;&lt;P&gt;I am looking for a firewall analizer which includes a feature for Policy Optimization and Cleanup.&amp;nbsp; If available, I would prefer an open source one, but I can look for another one.&amp;nbsp; I was wondering if you have any recommendations.&lt;/P&gt;&lt;P&gt;Thanks in advance for your help.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Paula&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:11:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-analizer-for-policy-optimization-and-cleanup/m-p/1862462#M489234</guid>
      <dc:creator>Maria Schiaffino</dc:creator>
      <dc:date>2019-03-11T22:11:03Z</dc:date>
    </item>
    <item>
      <title>Firewall analizer for Policy Optimization and Cleanup</title>
      <link>https://community.cisco.com/t5/network-security/firewall-analizer-for-policy-optimization-and-cleanup/m-p/1862463#M489235</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Several companies make such products:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.firemon.com/products/securitymanager/"&gt;http://www.firemon.com/products/securitymanager/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://algosec.com/en/products/firewall_analyzer"&gt;http://algosec.com/en/products/firewall_analyzer&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've not used them myself.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jan 2012 15:59:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-analizer-for-policy-optimization-and-cleanup/m-p/1862463#M489235</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2012-01-06T15:59:30Z</dc:date>
    </item>
    <item>
      <title>Firewall analizer for Policy Optimization and Cleanup</title>
      <link>https://community.cisco.com/t5/network-security/firewall-analizer-for-policy-optimization-and-cleanup/m-p/1862464#M489237</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Paula,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are a CSM customer, it currently has a couple of embedded tools for firewall policy analysis and rule consolidation.&amp;nbsp; I've found them to be incredibly handy in the past, particularly when performing routine audits/reviews.&amp;nbsp; Within the access policies section, you can perform the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1)Analysis - Analyzes the policy for duplicate/overlapping rules&lt;/P&gt;&lt;P&gt;2)Combine - Finds duplicate access control entries and presents you with the option of combining&lt;/P&gt;&lt;P&gt;3)Hit Count - Examine the usage of one or more rules&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See the following doc for more information on these features:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/security_management/cisco_security_manager/security_manager/4.2/user/guide/fwaccess.html"&gt;http://www.cisco.com/en/US/docs/security/security_management/cisco_security_manager/security_manager/4.2/user/guide/fwaccess.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Christopher&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jan 2012 23:16:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-analizer-for-policy-optimization-and-cleanup/m-p/1862464#M489237</guid>
      <dc:creator>Christopher Hayre</dc:creator>
      <dc:date>2012-01-06T23:16:40Z</dc:date>
    </item>
    <item>
      <title>Firewall analizer for Policy Optimization and Cleanup</title>
      <link>https://community.cisco.com/t5/network-security/firewall-analizer-for-policy-optimization-and-cleanup/m-p/1862465#M489239</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think the original poster asked for recommendations from folks with actual experiences using the products.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, I've used both Firemon, Algosec and Tufin products for firewall optimization and clean up.&amp;nbsp; All of the products rely heavily on the firewall logs.&amp;nbsp; The more archive log you have, the better the product is at optimizing and cleanup your rule base.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ranking based on my opinion:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tufin:&amp;nbsp; Excellent with checkpoint firewall, just OK for Cisco ASA firewall.&amp;nbsp; Tufin is an appliance&lt;/P&gt;&lt;P&gt;Firemon:&amp;nbsp; Really good with Cisco Pix firewalls.&amp;nbsp; Firemon is an appliance (a bundle of CentOS and Firemon Application)&lt;/P&gt;&lt;P&gt;Algosec:&amp;nbsp; OK with Cisco Pix IOS firewalls.&amp;nbsp; Algosec runs on Redhat Enterprise Linux&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 08 Jan 2012 15:29:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-analizer-for-policy-optimization-and-cleanup/m-p/1862465#M489239</guid>
      <dc:creator>david.tran</dc:creator>
      <dc:date>2012-01-08T15:29:21Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall analizer for Policy Optimization and Cleanup</title>
      <link>https://community.cisco.com/t5/network-security/firewall-analizer-for-policy-optimization-and-cleanup/m-p/3393621#M489242</link>
      <description>&lt;P&gt;You might find real user reviews for all the major &lt;A href="https://www.itcentralstation.com/categories/firewall-security-management/tzd/c632-sf-14" target="_self"&gt;firewall analyzers&lt;/A&gt; already mentioned on IT Central Station to be helpful.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Users interested in these solutions also read reviews for Skybox Security Suite. In his review, this Information Security Architect writes that the most valuable feature of Skybox is "&lt;SPAN&gt;the firewall change audit every week. Also, being able to track firewall ACL usage, so that we can produce semiannual reports on ACL usage and on shadowed and redundant rules on the firewall." You can read the rest of his review &lt;A href="https://www.itcentralstation.com/product_reviews/skybox-security-suite-review-50086-by-informatb8c7/tzd/c632-sf-14" target="_self"&gt;here&lt;/A&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Good luck with your search.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jun 2018 12:30:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-analizer-for-policy-optimization-and-cleanup/m-p/3393621#M489242</guid>
      <dc:creator>DanielleITCS</dc:creator>
      <dc:date>2018-06-04T12:30:54Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall analizer for Policy Optimization and Cleanup</title>
      <link>https://community.cisco.com/t5/network-security/firewall-analizer-for-policy-optimization-and-cleanup/m-p/3393674#M489244</link>
      <description>&lt;P&gt;It's bad form trolling a 6 year old post with links to your company's site.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jun 2018 14:13:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-analizer-for-policy-optimization-and-cleanup/m-p/3393674#M489244</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-06-04T14:13:51Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall analizer for Policy Optimization and Cleanup</title>
      <link>https://community.cisco.com/t5/network-security/firewall-analizer-for-policy-optimization-and-cleanup/m-p/3393682#M489246</link>
      <description>&lt;P&gt;So weird. When this came up on Google, it said that this thread was from 2017. I must have not been looking at the dates on the individual responses when I commented.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I sincerely apologize, that was my bad. Please feel free to delete if you're a moderator.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jun 2018 14:23:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-analizer-for-policy-optimization-and-cleanup/m-p/3393682#M489246</guid>
      <dc:creator>DanielleITCS</dc:creator>
      <dc:date>2018-06-04T14:23:51Z</dc:date>
    </item>
  </channel>
</rss>

