Runs entirely in your browser, nothing uploaded

Firewall hardening audits, without the upload.

Mizan reviews a FortiGate or Palo Alto configuration against vendor best-practice hardening guidance and returns a scored, multi-domain report of findings, fixes and references, all client-side in a browser tab.

No backend, no telemetry FortiOS & PAN-OS Instant, in-tab results
1 Drop your config
2 Audit & score
3 Explore exposure
4 Generate the document
mizansec.com
Mizan executive dashboard: overall risk posture, security score and findings breakdown for a multi-VDOM FortiGate
Built on Fortinet Hardening Guide PAN-OS Best Practices CIS Benchmarks NIST MITRE ATT&CK
Why Mizan

Everything a hardening review needs. Nothing it doesn't.

Purpose-built for firewall engineers. Deep vendor knowledge, honest analysis, visual answers instead of spreadsheets, and a report you can hand to a client.

Privacy-first

Your configuration never leaves your device.

No upload, no server, no processing anywhere but the tab in front of you. Parsing and every check run client-side, so a highly sensitive firewall backup stays on your machine.

  • Zero network calls with your config data
  • Works offline once the page is loaded
  • Nothing cached, logged, or transmitted
✓ Local parse✕ No upload
firewall-config.conf stays on device
🧠 Analysis engine runs in the tab
🚫 Network blocked
Multi-vendor

FortiOS and PAN-OS, understood properly.

Mizan reads the real CLI and XML schema of both platforms, including multi-VDOM FortiGates and multi-vsys, Panorama-managed and template-stacked Palo Altos, and keeps objects and policies scoped to where they belong.

  • FortiGate show full-configuration
  • PAN-OS set-format & XML, plus Panorama
  • VDOM / vsys aware, end to end
FortiOS 7.4 / 7.6 / 8.0 PAN-OS Panorama Multi-VDOM Multi-vsys
vdom: root 42 policies
vdom: dmz 17 policies
vsys: trust device-group
Scored report

18 domains, one 0–100 score, zero noise.

Every check is graded by severity and mapped to a concrete fix and a reference. The tool is conservative by design. It flags what's genuinely insecure, not what merely differs from a default, so the report survives review by security engineers.

  • System, admin, VPN, logging, routing, DoS & more
  • CIS · NIST · MITRE ATT&CK overlays
  • Per-finding fix commands and citations
Mizan per-VDOM findings breakdown with attack-surface, inspection, MFA and logging coverage metrics
Exposure & topology

See what the internet can actually reach.

An interactive map of interfaces, zones and VIPs, a packet path-trace across VDOMs, and an open-ports view that separates management surface from published services, so exposure is a picture, not a spreadsheet.

  • WAN-reachable VIP & management detection
  • Source-to-destination path trace
  • Per-VDOM open-port surface
Mizan path trace across a multi-VDOM FortiGate: Internet, through the firewall, to the destination, with every interface and IP mapped
Attack surface

Every open port, ranked by who can reach it.

Mizan enumerates every listener across all interfaces and VDOMs, separates management ports from published services, and flags what the internet can actually hit, so the real attack surface is a fact on the page, never a guess.

  • Management vs. published-service split
  • Internet-reachable listener detection
  • Per-port reachability & risk
Mizan open-ports view: attack-surface metrics and a per-interface listing of every listening port with reachability and risk
Visual analytics

Where the risk piles up, at a glance.

A risk Sankey from domain to severity, a treemap sized by finding count and coloured by worst severity, a posture radar across the scored domains and a score waterfall that shows exactly what each domain took off the total. Click any node or band to isolate its flows.

  • Risk flow, treemap, radar & waterfall
  • Click-to-isolate on every diagram
  • Radar overlay when comparing two configs
Mizan risk and posture analytics: a Sankey diagram flowing from audit domain to severity, with band width showing the number of findings
Traffic flow

The rule base as a flow, not a wall of text.

Zone-to-zone policy flow, an ingress-NAT-egress view, a zone heatmap and an attack-surface funnel, all drawn from the parsed rule base. Object blast radius shows every policy an address touches before you change it.

  • Zone → Zone and Ingress → NAT → Egress Sankeys
  • Zone heatmap & attack-surface funnel
  • Object blast radius before you touch a rule
Mizan Zone Flow Sankey: policy count as flow from each source zone to each destination zone, band width scaled by number of policies
Reachability

Ask one host what it can reach.

Give a source and a list of destinations and Mizan runs the same first-packet engine once per destination, fanning the results across egress interfaces. Green where a policy accepts, red where it is denied or unrouteable. Click a destination for the matching policy and route.

  • One source, many destinations, in one pass
  • Egress interface resolved per destination
  • Click through to the deciding policy and route
Mizan reachability fan trace: one source host probed against five destinations, showing two reachable through their egress interfaces and three blocked
Migration & hygiene

Find the dead weight before you migrate.

Unused objects, disabled policies, unreferenced profiles, shadowed and redundant rules, orphaned zones and a rule-base complexity score, the discovery pass every migration and clean-up starts with.

  • Shadow & redundancy analysis
  • Unused / unreferenced object hunting
  • Complexity & sizing snapshot
Unused objects 515
Disabled policies 70
Redundant rules 54
Orphaned zones 1
New

Generate the as-built document, not just the audit.

One click turns the parsed configuration into a professional Word document, a formal as-built and pre-migration discovery report, ready for an enterprise handover.

A handover document in seconds.

Cover page, auto table of contents, numbered chapters, running header and footer, across twelve chapters plus appendices covering system, interfaces, routing, policy, NAT, objects, VPN, profiles, logging and migration notes, for both vendors.

  • Formal DOCX with cover, TOC & page numbers
  • As-built + migration discovery in one
  • Honest by design, no fabricated values
firewall-documentation.docx
PAN-OS · CONFIDENTIAL
Contents
6 · Security policy
7 · NAT
8 · Objects & groups
12 · Migration notes
And more

A full console, not a checklist.

Compliance mapping

See findings rolled up against CIS, NIST and other frameworks, with pass/fail per family.

MITRE ATT&CK overlay

Relate exposure to adversary techniques so risk reads in terms leadership understands.

Compare configs

Diff two exports across policies, objects and settings, VDOM-aware and vendor-aware.

Risk acceptance

Accept a finding with a note and expiry; residual and gross scores update accordingly.

Parse coverage

Know exactly what share of the configuration the engine examined, with full transparency.

OT / ICS awareness

Industrial-protocol and Purdue-level context for firewalls guarding OT environments.

Where you work

Mizan lives inside Microsoft Teams.

Add it as a personal tab and run a hardening review without leaving Teams, the same client-side engine, the same privacy guarantees, embedded where your team already is.

▦ Documentation
◆ Dashboard · Grade B
▤ 11 findings
◈ Exposure map

Audit your firewall in the next five minutes.

Drop in a config, get a scored report, and generate the document, all in your browser.