List Info

Thread: RE: Best pracitce to analyze firewall policy




RE: Best pracitce to analyze firewall policy
country flaguser name
United States
2007-09-24 17:36:19

Take a look at these two products I use.
 
Kiwi Enterprises Syslog for the Pix
FireGen for Pix Log Analyzer
 
 
Roy Dumlao
 
 
 
 
 
 
-----Original Message-----
From: jctx09 [mailto:jctx09yahoo.com]
Sent: Tuesday, September 18, 2007 3:23 PM
To: PIX_Firewallyahoogroups.com
Subject: [PIX_Firewall] Best pracitce to analyze firewall policy


I'm a newbie to the PIX line. I have some questions that I hope you
guys can assist me with.

Two Questions:

1) What is the best/easiest way to document a current policy?
Spreadsheet?? I would like to know what ports (services) are open
and to where? Also duplicates, etc.? Would it be best just to put it
in a spreadsheet? Is there a tool for this?

2) Once an audit/analysis has been made, what is a good way to make
the new changes, if there are many? Would it best just to download
the config and modify it offline?

3) What is the method to see what rules are being hit the most so I
can rearrange the rules in the most logical, efficient order?

4) Is there standard Analysis checklist to go by when reviewing a
PIX firewall policy?

Any help is highly appreciated.

Thank you,

__._,_.___
.

__,_._,___
[1]

about | contact  Other archives ( Real Estate discussion Medical topics )