Firewalls are still the first line of defense for any network. To make them effective, your rulebase needs to be simplified and audited on a continuous basis. Every change deployed to the firewall has the potential to impact the behavior in unexpected ways and pose increased risk to the very assets you are trying to protect.
Athena FirePAC is your answer. Without Athena FirePAC, you may as well replace your firewall with an open router. FirePAC is a necessity for companies who value defense in depth and a comprehensive approach to security risk management.
Install it on your desktop in seconds, and generate reports that reveal exactly how your firewall is working. With FirePAC, you can use all of the time and money you'll save elsewhere.
Here are some key features of "Athena FirePac":
Firewall cleanup:
· Clean out all of the redundant, shadowed and overlapping rules that cause configuration errors, slow performance and make the firewall more costly and difficult to manage.
Security policy checks:
· Apply automated security templates to uncover exposures to critical hosts by identifying the dangerous services the firewall allows into the network.
Policy comparison:
· Validate how changes to the rules impact the overall behavior of the firewall. Determine what IP addresses might be at increased risk or what services are allowed by new versions of the configuration.
Services query:
· Determine all of the services allowed to a particular host or from a particular source. Identify what hosts may be exposed to a particular service. The policy query takes into account how all of the ACL, NAT and route rules are working together to control the behavior of the firewall.
What-if analysis:
· Understand how rule dependencies and complex interactions impact firewall behavior before changes are deployed to the network.
PCI compliance:
· Produce automated compliance reports that go beyond a checklist for minimal compliance. The FirePAC PCI audit pinpoints precisely what your firewall allows to reach your credit cardholder data.
Dangerous rules:
· Prioritize the riskiest rules causing the greatest exposure to your internal network. Problem rules can be modified to be more restrictive in order to pass security audits and ensure that the firewall is designed to mitigate risk.
Wizard-driven UI:
· Manage powerful analytics across multiple firewalls using FirePAC's intuitive interface and automated workflows. FirePAC makes it easy to understand the details about different firewall vendors using familiar views.
Migration support:
· Accelerate the migration process dramatically and ensure that the target policies are equivalent to the original. Athena FirePAC is the only solution that can provide remedies for the errors introduced through the conversion process.
Rule usage analysis:
· Simplify your rulebase by removing unused rules and objects. Move the most used rules to the top of the rulebase to improve performance.
Intelligent rule reordering:
· Generate an automatic optimized rule order based on the rule usage and rule dependency analysis. FirePAC ensures that performance optimization will not alter the security profile of the firewall.
Compliance comparison:
· Determine the impact of changes to your compliance profile. This report can be used to do periodic automated audits.
Rule and Object search:
· Search ACL rules to see if the change you want to make is already handled. Search your address and service objects by name or by content and find what rules and objects use the objects you are looking to modify or add.
SolarWinds Orion NCM integration:
· Use SolarWinds Orion NCM and Athena FirePAC together to determine how rule changes tracked by SolarWinds affect exposures to critical assets inside the network.
Group reports:
· Summarize the key findings on an inventory of firewalls including the number of security and compliance risks as well as opportunities for optimization.
Mass update facility:
· Upload a group of firewalls for analysis in a single operation
· VPN analysis Confirm the VPNs that are configured, the remote peers and the protected networks.
Scheduled analysis:
· Set-up your firewalls for automated periodic audits
Customized security checks:
· Build your own security templates. Customize a set of checks to audit the firewalls for compliance to your corporate policies.
Requirements:
· Cisco PIX
· Netscreen
· Checkpoint FW-1
· Java Runtime Environment (JRE) 5.0 and 6.0
· Microsoft Internet Explorer 6.0 SP1 (or later)
· Firefox 2.0 (or later)
· PDF reader for reading HTML/PDF reports
· Intel Pentium-compatible 2 GHz or faster
· 2 GB memory (RAM).
· 1 GB of drive space (and 5GB of temp space, up to 25MB of disk space for each firewall reports).
Limitations:
· Explore its functionality on data sample provided by Athena Security
· 30 days trial
· Nag Screen
What's New in This Release: [ read full changelog ]
· Object-cleanup support for Netscreen Checkpoint and PIX/ASA/FWSM firewalls.
· This feature determines the Rule usage, network object usage and service object usage by analyzing log data. The feature provides the hit counts for each rule along with the percentage usage of each source, destination and service object with in the rule. Also, it shows the aggregate usage of each service object used to specify service and network object used as either source or destination across all rules, based on the log entries.
· Security Technical Implementation Guide (STIG) best practice catalog included. This catalog gives excellent guidelines to the firewall security practices to be followed.
· Object-rationalization feature is supported for Cisco PIX/ASA/FWSM firewalls.
· All the object definitions and their variations for selected firewalls in the firewall inventory are exported into an Excel spread sheet. User can now easily refer to the object definitions and add modified object-definitions mapped...