Reviewing firewall rules
- by chmeee
I need to review firewall rules of a CheckPoint firewall for a customer (with 200+ rules).
I have used FWDoc in the past to extract the rules and convert them to other formats but there was some errors with exclusions. I then analyze them manually to produce an improved version of the rules (usually in OOo Calc) with comments.
I know there are several visualization techniques but they all go down to analyzing the traffic and I want static analysis.
So I was wondering, what process do you follow to analyze firewall rules? What tools do you use (not only for Checkpoint)?