Skip to content
Notifications
Clear all

Just built a tool to compare rule sets across deployments.

1 Posts
1 Users
0 Reactions
16 Views
(@ci_cd_crusader_v2)
Honorable Member
Joined: 5 months ago
Posts: 513
Topic starter   [#11617]

Spent the last two days wrestling with Firepower Management Center and its... let's call it "unique" approach to API consistency. Needed to audit rule sets across our production and DR deployments, and the built-in tools felt like they were designed to create consulting hours.

So I built a scrappy Python script that actually gives you a diff. Not a fancy UI, just a JSON output showing where your access policies diverge. The number of shadow rules and forgotten object overrides it found was depressing, but predictable.

It's basically a series of `GET` requests to the FMC API, normalizing the data, and then a comparison. The "fun" part is handling the API's love for nested dictionaries that change structure slightly between versions.

```python
def normalize_rule(rule):
"""Try to bring some sanity to FMC's rule representation."""
core_fields = {}
core_fields['name'] = rule.get('name')
core_fields['action'] = rule.get('action')
# Flatten source/destination objects and networks
core_fields['sources'] = _flatten_objects(rule.get('sourceNetworks', {}), rule.get('sourcePorts', {}))
core_fields['destinations'] = _flatten_objects(rule.get('destinationNetworks', {}), rule.get('destinationPorts', {}))
return core_fields
```

You run it against two FMCs (or take exports from different points in time), and it spits out which rules are missing, added, or have changed properties. No external dependencies beyond `requests`. It’s ugly, but it runs in a 20-line GitHub Actions workflow on a self-hosted runner, which is more than I can say for some of the enterprise "solutions" out there.

Anyone else forced to build their own tooling because the platform's native comparison is essentially worthless? I'm curious what others are comparing—just rule order and names, or digging into security intelligence feeds and variable sets too?


null


   
Quote