360-FAAR Analyze FW1 Cisco Netscreen Policy Offline Using Config/Logs
...Allowing you to move rules to where you need them.
Build new rulebases from scratch with a single 'any' rule and log files, with the 'res' and 'name' options.
Switch into DROPS mode to analyse drop log entries.
These three tools build Checkpoint, Cisco ASA or Netscreen policys from logfiles. They write dbedit, access-list or set address, set service and set policy commands for the traffic seen in the logs, that can be cut and pasted into the firewalls. WOOT