Firewall security assessment

MagenX examines FortiGate policy and reports which rules are permissive, which are unused, and what is genuinely reachable.

What is examined

FortiGate configuration is read through the FortiManager API with read permission. Policy is assessed as enforced, not as documented.

  • Permissive rules allowing any source, destination or service
  • Rules that carry no traffic
  • Services published to the internet through virtual IPs and port forwards
  • Inspection gaps where traffic passes unexamined
  • VPN and site-to-site links, and the networks they join

Reachability decided by the matching rule

A path is judged by the rule that actually matches the packet, in policy order, on the interface pair the traffic uses. An allow that sits behind a shadowing rule is reported as ineffective rather than as exposure.

What you get

Firewall findings are scored with Active Directory, Entra ID and network topology in one posture graph. Attack simulation walks that graph from a chosen foothold and names the single change that closes the most routes. Scheduled scans record what changed.

FAQ

Does this cover more than one firewall?

Yes. Policy is collected for the firewalls under FortiManager, and reachability is followed across them, so a path that crosses several devices is judged end to end.

Can this run on an isolated network?

Yes. Air-gapped installation is supported, and the assessment runs on hardware you control.

Every finding above is evidence you can hand to the person who owns the object.

Get a demo