AlgoSec for security auditing
Use Cases and Deployment Scope
We use AlgoSec to perform firewall audits ensuring there are no rule overlap and risky configurations are removed. It is also used to alert on any changes to the edge network environment and initially we were hoping the product would allow us to identify who made the changes as well, but it was unable to provide that ability.
Pros
- Traffic emulation to identify if IP traffic can flow between two points.
- Network device mapping is okay, but no better than other solutions.
- Identification of risky configurations and recommendations for remediation.
Cons
- Network mapping. Can't save any customized views unless you are an administrator.
- Rule identification. Really difficult to quickly identify rules that apply to ports and devices your are looking at.
- Can't identify who made firewall changes if AlgoSec does the change with its service account.
Likelihood to Recommend
It works okay for auditing existing network systems but seems to have trouble with cloud configurations.
