Mizan reviews a FortiGate or Palo Alto configuration against vendor best-practice hardening guidance and returns a scored, multi-domain report of findings, fixes and references, all client-side in a browser tab.
Purpose-built for firewall engineers. Deep vendor knowledge, honest analysis, visual answers instead of spreadsheets, and a report you can hand to a client.
No upload, no server, no processing anywhere but the tab in front of you. Parsing and every check run client-side, so a highly sensitive firewall backup stays on your machine.
Mizan reads the real CLI and XML schema of both platforms, including multi-VDOM FortiGates and multi-vsys, Panorama-managed and template-stacked Palo Altos, and keeps objects and policies scoped to where they belong.
show full-configurationEvery check is graded by severity and mapped to a concrete fix and a reference. The tool is conservative by design. It flags what's genuinely insecure, not what merely differs from a default, so the report survives review by security engineers.
An interactive map of interfaces, zones and VIPs, a packet path-trace across VDOMs, and an open-ports view that separates management surface from published services, so exposure is a picture, not a spreadsheet.
Mizan enumerates every listener across all interfaces and VDOMs, separates management ports from published services, and flags what the internet can actually hit, so the real attack surface is a fact on the page, never a guess.
A risk Sankey from domain to severity, a treemap sized by finding count and coloured by worst severity, a posture radar across the scored domains and a score waterfall that shows exactly what each domain took off the total. Click any node or band to isolate its flows.
Zone-to-zone policy flow, an ingress-NAT-egress view, a zone heatmap and an attack-surface funnel, all drawn from the parsed rule base. Object blast radius shows every policy an address touches before you change it.
Give a source and a list of destinations and Mizan runs the same first-packet engine once per destination, fanning the results across egress interfaces. Green where a policy accepts, red where it is denied or unrouteable. Click a destination for the matching policy and route.
Unused objects, disabled policies, unreferenced profiles, shadowed and redundant rules, orphaned zones and a rule-base complexity score, the discovery pass every migration and clean-up starts with.
One click turns the parsed configuration into a professional Word document, a formal as-built and pre-migration discovery report, ready for an enterprise handover.
Cover page, auto table of contents, numbered chapters, running header and footer, across twelve chapters plus appendices covering system, interfaces, routing, policy, NAT, objects, VPN, profiles, logging and migration notes, for both vendors.
See findings rolled up against CIS, NIST and other frameworks, with pass/fail per family.
Relate exposure to adversary techniques so risk reads in terms leadership understands.
Diff two exports across policies, objects and settings, VDOM-aware and vendor-aware.
Accept a finding with a note and expiry; residual and gross scores update accordingly.
Know exactly what share of the configuration the engine examined, with full transparency.
Industrial-protocol and Purdue-level context for firewalls guarding OT environments.
Add it as a personal tab and run a hardening review without leaving Teams, the same client-side engine, the same privacy guarantees, embedded where your team already is.
Drop in a config, get a scored report, and generate the document, all in your browser.