Skip to content
Notifications
Clear all

Just published a script to auto-generate security diagrams from Claw configs.

3 Posts
3 Users
0 Reactions
26 Views
(@devops_dad_joke)
Reputable Member
Joined: 7 months ago
Posts: 288
Topic starter   [#10034]

Alright folks, gather 'round. I just spent my weekend automating something that used to make me want to pull my hair out: security diagram documentation.

We've been piloting Absolute Secure Access (formerly NetMotion) for some of our field teams, and while the Claw configs are powerful, trying to visually map out the policies, tunnels, and resource access for a security review was... let's call it "manually painful." Every time there was a change, the Visio diagram was instantly outdated.

So I built a little Python script that parses exported Claw configuration files and spits out a Mermaid.js diagram. It's not perfect, but it gets you 90% of the way there in seconds instead of hours.

Here's the core of itβ€”it looks for the policy blocks and builds the nodes and links:

```python
# Example snippet - finds tunnel rules and maps sources to destinations
def parse_tunnel_policy(config_text):
tunnels = []
lines = config_text.split('n')
for i, line in enumerate(lines):
if 'policy tunnel' in line and 'from' in lines[i+1]:
source = lines[i+1].split('from ')[1].strip()
dest = lines[i+2].split('to ')[1].strip()
tunnels.append({'source': source, 'dest': dest})
return tunnels
```

You run it, pipe the output to a `.md` file, and your Git repo now has an auto-generated, always-update diagram showing exactly what talks to what. Huge win for audits and for new engineers trying to understand the secure access landscape.

Biggest pitfall I found? The script exposes just how convoluted some of our "temporary" exception policies had become. The diagram didn't lieβ€”we had a spaghetti monster. Time for some refactoring. 😅

Has anyone else tried something similar? Or found a better way to keep security topology visible without the manual overhead? I'm all ears. The goal is to make this stuff less "security theater" and more "here's the actual blueprint."

- tm



   
Quote
(@deborahw)
Reputable Member
Joined: 3 months ago
Posts: 358
 

This is the kind of tool that makes the paid "compliance and reporting" modules for these enterprise platforms look ridiculous. You're basically automating what they charge $15k a year for.

But I'm curious, does your script also flag weird shadow-rules? The kind of legacy "allow from any to any" that some vendor insists is necessary buried on page 200 of the config? That's the real value - catching the junk that the expensive platform's own dashboard probably glosses over with a green checkmark.


β€”DW


   
ReplyQuote
(@bench_beast)
Noble Member
Joined: 4 months ago
Posts: 723
 

> "does your script also flag weird shadow-rules?"

Not yet. I just ran it on a few Claw configs from our lab. The parser only maps tunnels and policies. It doesn't do any analysis on the rules themselves.

But you're right, that's where the real value is. I've been thinking about adding a pass that flags any rule with "any" in both source and destination. Or maybe a max entropy check on the policy names (the junk rules always have vague names like "temp-rule-3").

What's the threshold you use for calling something a shadow rule? I'd rather not just throw a red flag on every "allow any" because some are legit.


Benchmarks don't lie.


   
ReplyQuote