Firewall Management Tools: What to Look For

  • Post author:
  • Post category:Uncategorized

Managing firewalls at scale is a nightmare. Anyone who tells you otherwise is either lying or has never managed more than two firewalls. Once you get past a handful of devices across multiple vendors, you need tooling or you will drown in rule sets.

The problem

Firewall rules accumulate over time like sediment. Nobody wants to remove a rule because nobody knows what it does anymore. The person who created it left the company three years ago. The application it was created for was decommissioned but nobody told the network team. Before you know it, you have thousands of rules, half of which are redundant or obsolete, and your firewall is effectively a very expensive router.

What to look for in firewall management tools

  • Multi-vendor support – If you are a pure Cisco or pure Palo Alto shop, great. Most organizations are not. Your tool needs to speak Check Point, Cisco, Fortinet, Palo Alto, and Juniper at minimum.
  • Rule analysis and optimization – Can it identify redundant rules? Shadowed rules? Overly permissive rules? Rules that have never been hit? This is the core value proposition.
  • Change management – Can you track who changed what and when? Can you require approval workflows before changes are pushed? Can you roll back?
  • Compliance reporting – PCI, HIPAA, SOX all have firewall requirements. Your tool should be able to generate compliance reports without manual effort.
  • Topology awareness – Understanding the network topology means the tool can tell you if a proposed rule change will actually achieve what you want or if traffic will hit a different firewall first.
  • API access – If it does not have an API, it is not a serious tool. You need automation.

The tools

The major players in this space are Tufin, AlgoSec, FireMon, and Skybox. They all do roughly the same thing with different strengths. Tufin is strong on automation and orchestration. AlgoSec is good at business application connectivity. FireMon has solid real-time monitoring. Skybox does well with vulnerability context.

There are also open source options. fwbuilder has been around forever and works well for smaller environments. pfSense has decent built-in management for its own platform.

Pick the tool that fits your environment and your budget. But pick something. Manual firewall management does not scale.