Overall Satisfaction with FireMon
Currently, we are using FireMon to catalogue our firewall policies, assign owners to rules, and audit those rules.
- Policy Optimization - helping us remove shadow rules
- Rule analysis for gaps in security
- Unused rule identification
- Bugs, Bugs, Bugs, Bugs, Bugs
- Upgrades are often problematic.
- Sometimes what the reports show isn't what's in the database.
- Positive - ability to add rule owners has been a big deal
- Clean-Up of unused firewall rules has been helpful
- Global architecture searching - i.e. I'm looking for a single server and all of its touchpoints in our environment. Where do I search? FireMon, of course.
We have not used that to my knowledge yet. But, I know it's coming.
We are just now embarking on an automation effort. It would be good for us to learn more about these features and how to use them effectively.
We run reports from FireMon for our compliance teams and this has simplified our role in compliance audits.
Currently, we have not been using FireMon in this capacity. I would like to learn more about how to utilize this.
Tufin and Skybox are products that I've analyzed over the past few years, but never purchased.