|
In a Firewall device, there could be numerous rules/access-list defined to secure the network from external attacks. Out of the rules/access-list configured, there could be certain rules which would be most used and certain which are least used or never used. Firewall Analyzer captures the most used rules in the Top Used Rules as they would be available in the logs generated by Firewall. But, to get the Unused Rules, one needs to configure the Firewall Analyzer to fetch the complete rules from the device. Once, Firewall Analyzer fetches the complete rules configured in the Firewall, it can provide the Unused Rules view.
To view Unused Firewall Rules, configure the Firewall Analyzer by following the steps given below:
Device Rule Info
Devices Details
After entering and saving the Device Info values through the Firewall Analyzer GUI, the device, with details to fetch rules, is listed in the Device Details table. The details of the columns of the Device Details table are:
| Device Details | Description |
|---|---|
| Status | The status of fetching device rules/access control of the Firewall device |
| Devices Name | The names of the devices for which the rules will be fetched |
| Virtual FWs | For multi (vdom/context) Firewallls, this will display the number of vdoms/contexts associated to this specific device rule. Clicking on the count will show the details of the vdoms/contexts individually. Refer the screen shot below. |
| Edit | An icon to edit the details of the rules fetching info of the device. Click icon to edit the device info. |
| View Rules | An icon to view the rules fetched from the device. Click icon to view the device rules. |
| Unused Rules | An icon to view the rules fetched from the device, which were not used. Click icon to view the unused rules of the device. |
| Compliance Reports | The Compliance Reports related to Firewall Security Audit and Configuration Analysis. The report is available on clicking the link and the link text shows the time the compliance report was generated. You can instantly generate the Compliance report by clicking the icon. |
| View Config Changes | The configuration changes of the Firewall devices are reported. The report is available on clicking the link and the link text shows the time the configuration change report was generated. You can instantly fetch the current configuration change report by clicking the icon. |
| Last Update On | The time when the rules of the device were updated last. |
Virtual FWs

Select the option as per your requirement.
Next, there will be two tabs, Credentials and Choose Report.
The Credetials tab
You can configure the individual device credentials to fetch the rules and configuration from the device or you can create a common profile of device credential which can be used for a group of devices to fetch rules.
Fetching the rules directly from the device is supported for the following devices only:
For the rest of the devices, please use the Fetch Rules/Config > From File option. |
Fetch Rules/Config > From Device
Primary Info
Device Info |
Description |
|---|---|
Login Name |
While establishing connection with a device, if the device asks for a Login Name, set a value for this parameter. This parameter is Optional. |
Password |
To set the Password for accessing the device. |
Prompt |
The prompt that appears after successful login. |
Enable UserName |
When entering into privileged mode, some devices require UserName to be entered. Provide the username if prompted; otherwise leave this field empty. |
Enable Password |
This is for entering into privileged mode to perform configuration operations like backup/upload. This parameter is mandatory. |
| Enable Prompt | This is the prompt that will appear after going into enable mode. |
Both Primary and Secondary credentials (Login Name and Password) of the Firewalls are encrypted and stored in the Firewall Analyzer. |
Secondary Info
Click the link Secondary Info to view/enter values for these parameters. All the parameters are usually assigned with certain Standard Values by default. Such standard values have been filled for these parameters. Most of the devices would work well with these values and you need not edit these details unless you want to provide different set of details.
Device Info |
Description |
|---|---|
| IP Address | IP Address of the Firewall device to which the Firewall Analyzer will connect through FTP. See Note below. |
| Port (Telnet/SSH) | Port number of Telnet/SSH - 23 (for Telnet) and 22 (for SSH) by default. |
Login Prompt |
The text/symbol that appears on the console to get the typed login name is referred as login prompt. For example, Login: |
Password Prompt |
The text displayed on the console when asking for password. For example, Password: |
Enable User Prompt |
The text displayed on the console when asking for Enable UserName. For example, UserName: |
Enable Password Prompt |
The text displayed on the console when asking for password. For example, Password: |
The Choose Report tab
In the Fetch Rules from the device section, if the following message appears: 'Unable to generate compliance report. Reason: Failed to locate Nipper. Click here to enable it'. Carry out the procedure given at the end of the document. |
Generating Change Management Report is supported for the following devices:
|
Getting Rules/ Configuration Information from the individual virtual Firewalls (vdom/context)
|
For the complete procedure to export the configuration from various Firewalls in file format, refer the Exporting Configuration Files page.
Rule File
Configuration File
Only for Check Point Firewall
|
Testing the validity of device info
Device Info values entered through the Firewall Analyzer GUI should be accurate. Otherwise, Firewall Analyzer will not be able to establish connection with the device. To ensure the correctness of device info values, Firewall Analyzer provides the testing option. After entering the device info, you can test the values during which Firewall Analyzer will indicate if the values entered are valid. It will pinpoint the invalid values and you can carry out corrections accordingly.
To test the validity of device info, follow the procedure given below:
This updates the device info values in the database and then carries out the testing. The result of the testing will be shown in a separate window as below:
The testing result indicates valid device info values with a green 'tick' mark. The invalid values are marked as red cross marks. You need to change the invalid values. Alongside, the CLI command execution result (through which Firewall Analyzer ascertains the validity of device info values) is also displayed.
List Profile
Credential Profile Listing
Click the List Profile link to view the list device profiles to fetch the rules information from the devices. The Credential Profile Listing screen opens up.
On the top, there are links provided to add device info to fetch rules and to delete the device info. The links are:
After creating and saving the Device Profile values through the Firewall Analyzer GUI, the profiles, edit option, view/associate profile with devices to fetch rules, is listed in the Device Profile Details table. The details of the columns of the Device Profile Details table are:
| Device Profile Details | Description |
|---|---|
| Profile Name | The names of the profile, which will be used by the Firewall Analyzer to fetch the rules from the devices. |
| Edit | An icon to edit the profile details. Click icon to edit the device profile info. |
| View/Associate Devices | An icon to view the devices associated with the profile. Click icon to view the associated devices. If no device is associated, you will be prompted to associate a device. |
Delete Profile
Add Device Info Profile
Click the Add Device Info Profile link or New Profile link to create device info profiles to fetch the rules information from a set of common devices. The Add New Profile screen pops up.
You can configure the individual device credentials to fetch the rules from the device or you can create a common profile of device credential which can be used for a group of devices to fetch rules.
Primary Info
Device Info
Description
Login Name
While establishing connection with a common set of devices, if the devices ask for a Login Name, set a value for this parameter. This parameter is Optional.
Password
To set the Password for accessing the common set of devices.
Prompt
The prompt that appears after successful login.
Enable UserName
When entering into privileged mode, some common set of devices require UserName to be entered. Provide the username if prompted; otherwise leave this field empty.
Enable Password
This is for entering into privileged mode to perform configuration operations like backup/upload. This parameter is mandatory.
Enable Prompt This is the prompt that will appear after going into enable mode.
Both Primary and Secondary credentials (Login Name and Password) of the Firewalls are encrypted and stored in the Firewall Analyzer.
Secondary Info
Click the link Secondary Info to view/enter values for these parameters. All the parameters are usually assigned with certain Standard Values by default. Such standard values have been filled for these parameters. Most of the devices would work well with these values and you need not edit these details unless you want to provide different set of details.
Device Info
Description
Port (Telnet/SSH) Port number of Telnet/SSH - 23 (for Telnet) and 22 (for SSH) by default.
Login Prompt
The text/symbol that appears on the console to get the typed login name is referred as login prompt. For example, Login:
Password Prompt
The text displayed on the console when asking for password. For example, Password:
Enable User Prompt
The text displayed on the console when asking for Enable UserName. For example, UserName:
Enable Password Prompt
The text displayed on the console when asking for password. For example, Password:
Select Device Type Select the type of device (Cisco/Fortigate/Netscreen) from the drop down list.
Assign Profile
Click the Assign Profile link to associate devices to device profiles to fetch the rules information from the devices. The Associate Profiles to Devices screen opens up.
The Compliance Reports related to Firewall Rules/Policies Configuration/Changes.
After associating the devices to Device Profiles the profiles and the associated devices are listed in the Device Profile Details table.
Getting Rules/ Configuration Information from the individual virtual Firewalls (virtual domain) If you want to fetch the rules/configurations from the individual virtual Firewalls (virtual domain) separately, select the option 'Display Virtual Domains in the below resources list.' in Associate Profiles to Devices page. It lists both the virtual Firewalls (virtual domain) and the physical devices in the Select Device drop down list. |
Trouble Shooting: If the following message appears in the Compliance Reports field, enable Nipper. 'Unable to generate compliance report. Reason: failed to locate nipper. Click here to enable it' |
Procedure to enable Nipper
In the Compliance Report field, the following message appears: 'Unable to generate compliance report. Reason: Failed to locate Nipper. Click here to enable it'. What should I do?
Supported Platform:
Prerequisite:
The GNU/Linux platform requires Qt 4.5 to be installed. Your package manager system should automatically install this for you.
Steps:
|