Custom Risk Profiles | Firewall Analyzer

The Custom Risk Profiles feature allows administrators to define customized security risk criteria based on their organization’s specific security requirements. Using this feature, users can create multiple custom risk criteria lists, group them under a custom risk profile, and associate those profiles with firewall devices. This enables more precise security analysis by tailoring risk assessments to match business policies, compliance requirements, and operational priorities. When a custom profile is not assigned to a device, the system automatically falls back to the standard risk profile, ensuring uninterrupted risk analysis.

Custom Risk Profile in Firewall Analyzer

What this page covers

Key Capabilities

  1. Custom Profile Creation : Administrators can create custom risk profiles by selecting specific risks and defining the conditions under which they should be triggered.
  2. Device Association : Custom risk profiles can be mapped to individual devices or groups of devices to apply targeted risk analysis.
  3. Default Profile Handling : If a device is not associated with a custom profile, the standard risk profile will automatically be applied.
  4. Profile Extensions : Organizations can extend standard risk profiles with additional custom risk criteria to address unique security needs.
  5. Dynamic Risk Evaluation : Risk assessments are performed dynamically based on the current firewall configuration, ensuring accurate and up-to-date risk detection.

Risk Analysis Capabilities

Multi-Condition Risk Criteria

Custom risks can be defined using multiple parameters, including:

  • IP addresses
  • Ports
  • Zones
  • Protocols
  • Actions
  • Rule status

Advanced Operators

The feature supports multiple operators for building flexible risk criteria, such as:

  • Equals / Not equals
  • In / Not in
  • Range
  • Contains
  • Greater than / Less than

Creating a Custom Risk

Custom risks allow organizations to define their own rule-level security checks.

To add a custom risk:

  1. Navigate to Rule Management → Risk.
  2. Click Add Custom Risk.
  3. Enter the following details:
    • Risk Name
    • Severity
    • Description
    • Recommendation
  4. Define the Risk Criteria:
    • Select the required field (e.g., Source Object).
    • Choose the condition (e.g., Equals).
    • Specify the value (e.g., Any).
    • Use + to add additional conditions if required.
  5. Click Save.

Once created, the custom risk will be available in the Risk view and applied during rule analysis.

 Add Custom Risk Profile in Firewall Analyzer

Creating Custom Risk Profiles

To create a custom risk profile:

  1. Navigate to Rule Management → Risk → Custom Risk Profiles.
  2. Click Actions.
  3. Select Create Profile.
  4. Enter the following details:
    • Profile Name
    • Description
  5. Select the risks to be included in the profile.
  6. Associate the profile with the required firewall devices.
  7. Save the profile.

Once created, the profile will appear in the Profile-Based View.

Create Custom Risk Profile in Firewall Analyzer

Associating Profiles with Devices

  1. Open the Custom Risk Profiles page.
  2. Switch to Device-Based View.
  3. Select the required device.
  4. Assign:
    • Default Risk Profile
    • Additional Associated Profiles

The selected profile will be used to evaluate firewall rules for risks.

Create Custom Risk Profile in Firewall Analyzer

Note: Interface-specific risks are currently not supported for Check Point, Cisco Meraki, Barracuda, F5 Firewall and Netfilter devices. Any selected interface-specific risks will not be applied to these devices.

Accessing Custom Risk Profile

To access the Custom Risk Profiles page:

  1. Navigate to Rule Management from the top navigation menu.
  2. Click the Risk tab in the Rule Management module.
  3. Select the Custom Risk Profiles tab available next to Summary and Rules.

Once selected, the Custom Risk Profiles page will open, displaying the risk profile management interface.

Create Custom Risk Profile in Firewall Analyzer

Page Overview

Summary Widgets

  • Firewall — Total number of firewalls monitored.
  • Custom Risk Profiles — Number of custom profiles created.
  • Firewall using Standard profile as Default — Devices using default profile.
  • Firewall using Custom profile as Default — Devices using custom profile as default.

View Selection

The View dropdown allows administrators to change how risk profile information is displayed.

View TypeDetails DisplayedUse Case
Profile Based ViewProfile Name
Profile Description
Associated Devices
Default device assignments
Risk counts
Applied risks
Useful for managing or reviewing specific risk profiles.
Device Based ViewDevice Name
Default Risk Profile
Other associated profiles
Helps verify which profiles are applied to each device.

Custom Risk Profile in Firewall Analyzer

Profile List

FieldDescription
Profile NameName of the risk profile.
DescriptionBrief description of the profile configuration.
Associated DevicesDevices where the profile is applied.
Default ForDevices where the profile is set as default.
Applied RisksNumber of risks categorized by severity (Critical, High, Medium, Low, Attention).
Risk ListPreview of risks included in the profile.

Administrators can edit or delete custom profiles from this section.

Risk List

ItemDescription
System-defined risksDefault risks provided by the system.
Custom risksUser-created risk definitions.
Risk NameName of the risk.
DescriptionDetails about the risk.
Risk TypeIndicates whether the risk is Default or Custom.
Severity LevelDefines the impact level of the risk.

Custom Risk Profile in Firewall Analyzer

For more information about Custom Risk Profiles, refer to the FAQs section.

Benefits of Custom Risk Profiles

  1. Custom Security Policies : Define risk criteria based on organizational requirements instead of relying only on predefined risks.
  2. Flexible Device Management : Apply different risk profiles to different firewall environments such as data centers, branches, or external networks.
  3. Automated Risk Monitoring : Firewall Analyzer automatically generates risk reports based on the default assigned profile. If no custom profile is set, the system falls back to the standard profile.
  4. Centralized Risk Management : Manage all risk profiles and configurations from a single interface.
  5. Improved Risk Visibility : Risks are categorized by severity levels (Critical, High, Medium, Low, Attention), helping administrators prioritize remediation efforts.
A single platter for comprehensive Network Security Device Management