03-03-2024 02:08 PM
Hi All,
I have recently started a new position in which I am facing a daunting task of cleaning up of ACP. What I would like to understand is what should be my approach to do it. There seems to be a lot of stale entries in there but I have no way of knowing at the moment of the6 would be utilised again or not.
Can you please suggest a good way of taking this up.
Saurav
Solved! Go to Solution.
03-03-2024 03:28 PM
Hi Saurav,
This is the strategy that I follow:
1. Disable unused rules
2. Disable covered rules (Rules which are covered by another rule, redundant rules)
3. Clean up duplicate objects (Objects pointing to same IP, IP set)
4. Check for ANY rules, to optimise and cover only required ports
5. Look at reordering or placement of the remaining rules
I suggest looking at Algosec, and see if your business would be willing to spend money on it! If not, simply, spin up a 30 days trial to understand the product and optimize your exisiting firewall, and conducting a PoC later to place it better to the board to see if they would be interested. This will definitely help you with the clean up work in future.
This is only a personal recommendation.
Please mark this helpful if you are happy with the response, and accept the solution.
03-03-2024 03:28 PM
Hi Saurav,
This is the strategy that I follow:
1. Disable unused rules
2. Disable covered rules (Rules which are covered by another rule, redundant rules)
3. Clean up duplicate objects (Objects pointing to same IP, IP set)
4. Check for ANY rules, to optimise and cover only required ports
5. Look at reordering or placement of the remaining rules
I suggest looking at Algosec, and see if your business would be willing to spend money on it! If not, simply, spin up a 30 days trial to understand the product and optimize your exisiting firewall, and conducting a PoC later to place it better to the board to see if they would be interested. This will definitely help you with the clean up work in future.
This is only a personal recommendation.
Please mark this helpful if you are happy with the response, and accept the solution.
03-03-2024 09:44 PM
We use AlgoSec Firewall Analyzer for this. I would suggest setting this up and then send syslog to it. Right away after running an analysis report you will be able to identify covered rules, duplicate objects, etc. and then after letting AlgoSec collect logs for a little while you will have an accurate idea of which rules are being hit and you can drill down into what ports and IPs are being used on those rules to tighten up even more.
03-03-2024 10:38 PM
Thank you guys.. I will look at Algosec for this...
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide