FireMan reviews a FortiGate or Palo Alto configuration against vendor best-practice hardening guidance and returns a scored, multi-domain report — findings, fixes and references — all client-side in a browser tab.
Purpose-built for firewall engineers. Deep vendor knowledge, honest analysis, and a report you can hand to a client.
No upload, no server, no processing anywhere but the tab in front of you. Parsing and every check run client-side, so a highly sensitive firewall backup stays on your machine.
FireMan reads the real CLI and XML schema of both platforms — including multi-VDOM FortiGates and multi-vsys, Panorama-managed and template-stacked Palo Altos — and keeps objects and policies scoped to where they belong.
show full-configurationEvery check is graded by severity and mapped to a concrete fix and a reference. The tool is conservative by design — it flags what's genuinely insecure, not what merely differs from a default — so the report survives review by security engineers.
An interactive map of interfaces, zones and VIPs, a packet path-trace across VDOMs, and an open-ports view that separates management surface from published services — so exposure is a picture, not a spreadsheet.
FireMan enumerates every listener across all interfaces and VDOMs, separates management ports from published services, and flags what the internet can actually hit — so the real attack surface is a fact on the page, never a guess.
Unused objects, disabled policies, unreferenced profiles, shadowed and redundant rules, orphaned zones and a rule-base complexity score — the discovery pass every migration and clean-up starts with.
One click turns the parsed configuration into a professional Word document — a formal as-built and pre-migration discovery report, ready for an enterprise handover.
Cover page, auto table of contents, numbered chapters, running header and footer — twelve chapters plus appendices covering system, interfaces, routing, policy, NAT, objects, VPN, profiles, logging and migration notes, for both vendors.
See findings rolled up against CIS, NIST and other frameworks, with pass/fail per family.
Relate exposure to adversary techniques so risk reads in terms leadership understands.
Diff two exports — policies, objects and settings — VDOM-aware and vendor-aware.
Accept a finding with a note and expiry; residual and gross scores update accordingly.
Know exactly what share of the configuration the engine examined — full transparency.
Industrial-protocol and Purdue-level context for firewalls guarding OT environments.
Add it as a personal tab and run a hardening review without leaving Teams — the same client-side engine, the same privacy guarantees, embedded where your team already is.
Drop in a config, get a scored report, and generate the document — all in your browser.