FW-OPT
FW-OPT · POLICY ANALYZER

Firewall Rule Optimizer

Palo Alto, Fortinet, Cisco, Check Point & pfSense/OPNsense policy analysis — shadowing, redundancy, merges, exposure, compliance & ordering
NETBRIGHTEnterprise IT Solutions

Configuration input

auto-detect
Archive Multiple config files found — pick one, or “Merge all”.
Add hit-count data (optional) — finds unused rules & data-driven ordering

Paste rule hit counts as name,count or name count (one per line). Accepts show rule-hit-count / diagnose firewall iprope output too. Match is by rule name, falling back to rule number.
Note: a backup / exported config does not contain hit counts — pull these from the live device (Palo Alto: show rulebase security rules hit-count, Fortinet: get firewall policy, Cisco: show access-list).

Threat intel — CISA KEV (optional): flag exposed services with actively-exploited CVEs

Correlates services your rules expose (RDP, SMB, SSL-VPN, databases…) with the CISA Known Exploited Vulnerabilities catalog. Privacy: fetching downloads a public file only — your configuration is never sent anywhere. Air-gapped? Download the JSON from cisa.gov yourself and load it here. Context only — does not change the score.

No rules parsed yet.
Working…
Supported formats & what gets checked
  • Palo Alto: set rulebase security rules … CLI (set-format), plus set address / set service objects for resolution.
  • Fortinet: config firewall policy blocks, plus config firewall address / service custom for resolution.
  • Cisco: ASA access-list … extended permit/deny & IOS ip access-list extended, with object / object-group resolution and ACL-scoped ordering.
  • Check Point: SmartConsole rulebase export — CSV / TSV with Name, Source, Destination, Service, Action, Track columns (header auto-detected).
  • pfSense / OPNsense: config.xml backup — <filter><rule> rules with aliases resolved (host / network / port), plus OPNsense plugin rules.
  • Checks: shadowed & redundant rules, mergeable rules, overly-permissive / any-any exposure, logging gaps, ordering, CIS/PCI compliance, and (with hit data) unused rules. A composite Security Score is computed from these.

Results

Paste a config and hit Analyze to see your security score and optimization findings.
VDOM scope Multiple VDOMs detected — pick one for full-fidelity analysis, or “All” for a merged overview.
Security score
0
Findings
Top risks
Critical / high Medium Low / info Pass / good

Zone exposure matrix

allow paths

Which zones can talk to which — each cell counts the active allow rules from the row zone to the column zone. Red = an any-service / any-any allow path; amber = a broad (“any” field) allow; hover a cell for the rule names.

Findings

Severity

Optimized configuration


    

What-if simulator

pre-change check

Test a proposed rule against the analyzed rule base before you commit it — see if it would be dead on arrival, override existing rules, weaken security, and how the score would change.

Insert at

Packet tracer

policy lookup

Enter a flow (source, destination, port) and see which rule wins and whether it's allowed or denied — first-match, in order, like test security-policy-match / packet-tracer.

Optional: source / destination zone & application (Palo Alto)

Config diff

change review

Paste a previous version of the same config (same vendor) to see what changed — rules added, removed, and modified field-by-field. Great for change-window review and audit evidence.

Parsed rule base