Re: [fw-wiz] Recommendations on modeler/change manger for PIX & FWSM



> On 1/24/06, Cary, Kim <Kim.Cary@xxxxxxxxxxxxxx> wrote:
> > Been watching the list with interest for about 6 months! Thanks for the good
> > discussion.
> >
> > We have several PIX & FWSM (PIX Blades) our team is managing. We've been
> > using PDM (Cisco's Java tool for managing PIX) for distributed
> > administration, but we've been getting tired of its shortcomings in
> > documenting our rules. Also, we'd like to find something that handles change
> > management (reporting, maybe rollback or state snapshots) and modeling (if
> > traffic from 'here' starts to go 'there' what does the firewall do).
>

I've implemented a perl script and SVN based solution here for
managing config changes - archiving/versioning them. Depending on
where the devices are located in relation to where you run the
scripts from it can wait to receive a trap stating the config has
changed or run from a cron job and go grab it. E-mail me off-list and
I'll give you what I've got.

Can't help with the rest - though you could, in theory, use these
scripts as a basis for creating new configs to upload programmaticly.
The perl modules available are pretty robust.
_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxx
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards



Relevant Pages

  • A Framework to automatically configure a Kernel
    ... automatically generates a Kernel-Configuration. ... I've right-now almost finished a framework that generates a ... .config file based on the target system. ... Those scripts answers are depending on the ...
    (Linux-Kernel)
  • Re: Debian Security - Configs, etc...
    ... What can you do to restrict access to the services from the network by ... (most firewall scripts will also provide protection ... What can you do in the config of each network application to limit access ...
    (comp.os.linux.security)
  • Re: accessing $_GET implicitly
    ... There is a PHP configuration directive (i.e. something you put in the config ... scripts just as if they're day-to-day script variables. ... As of PHP 4.2.0 this ... that makes all my form variables appear as $form_blah, ...
    (comp.lang.php)
  • Re: howto make sysintall
    ... I think John was right that it is better to build my own mfsroot and ... then make config scripts etc. ... > You can run a command to generate a config file that you then include. ... > This is just the part to setup the install media. ...
    (freebsd-hackers)
  • RE: Access to scripts(startup/shutdown) under computers
    ... users (in Users config) is NOT there wheras it has been previously. ... Startup/Shutdown Scripts are for Computers (in Computer ... Logon/Logoff Scripts are for users. ...
    (microsoft.public.windows.server.active_directory)