Skip to content
NGFW ruleset review...
 
Notifications
Clear all

NGFW ruleset reviewer tools - do you just manually check or use something else?

2 Posts
2 Users
0 Reactions
26 Views
(@infra_auditor_nina)
Honorable Member
Joined: 6 months ago
Posts: 467
Topic starter   [#10390]

I've been handed the dubious honor of "reviewing" our new NGFW ruleset before it hits production. It's several thousand lines of "allow any any" with vendor-specific objects sprinkled in like magic dust. The security lead swears it's fine because the "intent-based" policies will be enforced by the magical L7 engine.

I call nonsense. I need to audit this thing for compliance (PCI-DSS 1.2.x, for starters) and basic sanity.

My question: does anyone here actually use a dedicated tool, or is it all manual slogging in Excel and Notepad++?

* I know some vendors have "ruleset analyzers" that find shadowed rules, but they're usually vendor-locked and ignore compliance mapping.
* I've seen scripts that convert to a generic JSON and then run checks. Example of a basic shadowed rule finder I threw together:

```python
# Pseudo-code for a simple check
def find_shadowed(rules):
for i, higher_rule in enumerate(rules):
for lower_rule in rules[i+1:]:
if (higher_rule.src_cidr.contains(lower_rule.src_cidr) and
higher_rule.dst_cidr.contains(lower_rule.dst_cidr) and
higher_rule.port_range.contains(lower_rule.port_range) and
higher_rule.action == "allow"):
yield (higher_rule, lower_rule)
```
* But that doesn't catch business logic errors, like allowing `ANY` to the PCI segment on port 22.

So, what's your process? Do you just rely on the vendor's own tools and hope, or have you built/bolted together a proper review pipeline that can spit out a compliance gap report? Bonus points if it works across Palo Alto, Fortinet, and Check Point without requiring a theology degree in each.

- Nina


- Nina


   
Quote
(@laura)
Estimable Member
Joined: 3 months ago
Posts: 64
 

That sounds like a nightmare. A few thousand lines of "allow any any" would freak me out too, even with L7 stuff.

I'm really new to this side of things, so maybe this is a dumb question, but... you mentioned converting to generic JSON for checks. Is that something people actually do at scale? Like, is there a common format different tools can read, or do you have to write a new parser for every firewall brand?

Also, PCI-DSS 1.2.x feels like a huge manual checklist. Does any tool actually map rules to those specific requirements, or is that always a human job?



   
ReplyQuote