Re: [fw-wiz] Recommendations on modeler/change manger for PIX & FWSM

> On 1/24/06, Cary, Kim <Kim.Cary@xxxxxxxxxxxxxx> wrote:
> > Been watching the list with interest for about 6 months! Thanks for the good
> > discussion.
> >
> > We have several PIX & FWSM (PIX Blades) our team is managing. We've been
> > using PDM (Cisco's Java tool for managing PIX) for distributed
> > administration, but we've been getting tired of its shortcomings in
> > documenting our rules. Also, we'd like to find something that handles change
> > management (reporting, maybe rollback or state snapshots) and modeling (if
> > traffic from 'here' starts to go 'there' what does the firewall do).

I've implemented a perl script and SVN based solution here for
managing config changes - archiving/versioning them. Depending on
where the devices are located in relation to where you run the
scripts from it can wait to receive a trap stating the config has
changed or run from a cron job and go grab it. E-mail me off-list and
I'll give you what I've got.

Can't help with the rest - though you could, in theory, use these
scripts as a basis for creating new configs to upload programmaticly.
The perl modules available are pretty robust.
firewall-wizards mailing list

Relevant Pages

  • A Framework to automatically configure a Kernel
    ... automatically generates a Kernel-Configuration. ... I've right-now almost finished a framework that generates a ... .config file based on the target system. ... Those scripts answers are depending on the ...
  • Re: Debian Security - Configs, etc...
    ... What can you do to restrict access to the services from the network by ... (most firewall scripts will also provide protection ... What can you do in the config of each network application to limit access ...
  • Re: Seeking help with relative and absolute paths
    ... can be accommodated in the scripts and pages that I write I am ... If you create your config file and put your constants in it, any script that includes that config file will have that constant visible which at this point is not much functionally difference then setting data for each page, but this provides a single location for setting site wide data. ... I use the config and defines for setting SQL criteria, typing friendly root paths and server side peculiarities. ...
  • Re: accessing $_GET implicitly
    ... There is a PHP configuration directive (i.e. something you put in the config ... scripts just as if they're day-to-day script variables. ... As of PHP 4.2.0 this ... that makes all my form variables appear as $form_blah, ...
  • Re: multi-master with mysql backend
    ... out the config with the "master" config, and now you have a new master. ... Just be sure the updates go to the server listed in the MNAME field of the ... and two scripts that generate either master or slave config. ...