Results of analysis carried out for:

Firewallsample
TypeCisco PIX
Date11/25/2008 3:28:46 PM

Statistics on the analysis:

Rules categoryNumber droppedPercentage
Log analysis 200 48.66 %
Redundant 6 1.459 %
Grouped 23 5.596 %
Unused objects 33 8.029 %



Table of Content

1. Result of Log Analysis
2. Result of Redundant Analysis
3. Result of Group Analysis
4. Result of Unused Objects Analysis
5. Result of Undeclared Source Host Analysis
6. Result of Undeclared Destination Host Analysis
7. Result of Undeclared Services Analysis




Results of log analysis

The following policies can be dropped based on log analysis


IDSource HostsDestination HostsServicesAction
8anyany6129deny
24anysample_3480permit
31sample_16/24sample_21161permit
33sample_16/2210.0.0.78/3253permit
41any10.0.0.25/3280permit
5010.0.0.20/32any443permit
5110.0.0.25/32any443permit
52sample_20sample_418080permit
53any10.0.0.152/3280permit
54any10.0.0.152/32443permit
57anysample_2325permit
60any10.0.0.95/3280permit
61sample_4510.0.0.158/32577permit
6610.0.45.5/3210.0.0.68/3223permit
6710.0.0.100/3210.0.0.68/32anypermit
6810.0.0.100/32sample_7anypermit
6910.0.6.198/3210.0.0.68/32anypermit
7010.0.6.198/32sample_7anypermit
7110.0.0.45/3210.0.0.68/32anypermit
7310.0.0.225/3210.0.0.66/32radius:radius-acctpermit
7410.0.0.225/3210.0.0.67/32radius:radius-acctpermit
7564.104.205.63/32sample_3323permit
76sample_2210.0.238.77/321521permit
77sample_2210.0.238.77/321521permit
7810.0.0.224/28sample_21515permit
7922.247.15.77/3210.0.0.169/3222permit
8110.0.0.226/3210.0.0.66/32radiuspermit
8210.0.0.226/3210.0.0.66/32radius-acctpermit
8322.234.153.202/32anyanydeny
8410.0.0.226/3210.0.0.67/32radiuspermit
8510.0.0.226/3210.0.0.67/32radius-acctpermit
86any10.0.0.92/3281permit
87any10.0.0.92/32449permit
9810.0.6.54/3210.0.0.164/32echo-replypermit
9910.0.6.198/3210.0.0.164/32mask-replypermit
10010.0.6.198/3210.0.0.164/32echo-replypermit
10110.0.3.140/3210.0.0.164/32mask-replypermit
10210.0.3.140/3210.0.0.164/32echo-replypermit
10310.0.3.133/3210.0.0.164/32mask-replypermit
10410.0.3.133/3210.0.0.164/32echo-replypermit
105sample_4310.0.0.164/32mask-replypermit
106sample_4310.0.0.164/32echo-replypermit
10710.0.3.137/3210.0.0.164/32mask-replypermit
10810.0.3.137/3210.0.0.164/32echo-replypermit
10922.247.15.77/3210.0.0.168/3223permit
11022.247.15.77/3210.0.0.168/3221permit
11122.247.15.77/3210.0.0.169/3223permit
11222.247.15.77/3210.0.0.169/3221permit
113anysample_76970:7170permit
114anysample_86970:7170permit
115sample_53sample_52sample_54permit
12010.0.137.194/3210.0.137.194/3220permit
122any10.0.0.24/3280permit
135sample_84sample_24sample_86permit
138sample_1anysample_106permit
143anysample_1sample_113permit
144anysample_1sample_112permit
15210.0.0.12/32sample_11163permit
158anyanyanypermit
159sample_36any53permit
160sample_36any53permit
163sample_10anyanypermit
164sample_11anyanypermit
16510.0.0.66/32any53permit
16810.0.0.67/32any53permit
16910.0.0.67/32any53permit
170sample_19any25permit
171sample_18any25permit
17310.0.0.154/32any25permit
17510.0.0.143/32sample_438080permit
176sample_13anyanypermit
177sample_17anysample_17permit
178sample_17anyanypermit
180sample_172anyanypermit
182sample_8any8080permit
184sample_7any21permit
189any10.0.0.20/3280permit
191any10.0.0.25/32443permit
192any10.0.0.25/3280permit
19310.0.0.20/32any443permit
19610.0.0.20/32any80permit
19710.0.0.136/32sample_4021permit
19810.0.0.136/32sample_3921permit
19910.0.0.149/32sample_4021permit
20010.0.0.149/32sample_3921permit
20110.0.0.151/32sample_4021permit
20210.0.0.151/32sample_3921permit
20310.0.0.153/32sample_4221permit
20410.0.0.76/32any21permit
20510.0.0.76/32any8080permit
20610.0.0.76/32any80permit
20710.0.0.73/32any25permit
208sample_23any25permit
20910.0.0.155/32195.229.49.177/32443permit
21010.0.0.155/32195.229.49.177/328080permit
21410.0.0.157/3210.0.0.12/328080permit
21510.0.0.157/3210.0.0.12/321494permit
21610.0.0.157/3210.0.0.12/321604permit
21710.0.0.68/3210.0.0.100/32anypermit
218sample_710.0.0.100/32anypermit
21910.0.0.68/3210.0.0.100/32anypermit
220sample_710.0.0.100/32anypermit
221sample_2910.0.219.53/32443permit
222sample_2910.0.0.12/32443permit
223sample_2910.0.0.134/32443permit
224sample_2910.0.0.12/3221permit
22510.0.0.158/3213.86.133.55/32anypermit
22610.0.0.210/3210.0.134.90/329009permit
22710.0.0.100/3210.0.0.100/328080permit
22810.0.0.155/3210.0.0.177/328080permit
22910.0.0.155/3210.0.0.177/32443permit
23010.0.0.250/3210.0.0.68/3223permit
23110.0.0.250/3210.0.0.68/3223permit
23210.0.0.250/3210.0.0.68/328081permit
23310.0.0.250/3210.0.0.68/328081permit
23410.0.0.250/3210.0.0.69/3223permit
23510.0.0.250/3210.0.0.69/3223permit
23610.0.0.250/3210.0.0.69/328081permit
23710.0.0.250/3210.0.0.69/328081permit
23810.0.238.77/32sample_221521permit
23910.0.238.77/32sample_221521permit
24010.0.0.162/32sample_47anypermit
24110.0.0.162/32sample_47isakmppermit
24210.0.0.162/32sample_4710000permit
24310.0.0.162/3210.0.0.140/32anypermit
24410.0.0.165/3210.0.0.144/32443permit
24810.0.15.235/32anyanydeny
25010.0.0.226/3210.0.0.66/321646permit
25110.0.0.226/3210.0.0.67/321646permit
25210.0.0.226/3210.0.0.67/321645permit
25310.0.0.163/3210.0.3.133/328080permit
25410.0.0.163/3210.0.3.137/328080permit
25510.0.0.163/32sample_438080permit
25610.0.0.163/3210.0.3.140/328080permit
25710.0.0.164/32sample_49echopermit
25810.0.0.164/32sample_49mask-requestpermit
25910.0.0.91/32any80permit
26010.0.0.91/32any443permit
26110.0.0.108/32207.46.197.119/3280permit
264sample_7any2000:2001permit
265sample_8any2000:2001permit
266sample_7any5005permit
269sample_8any5000permit
270sample_7any1755permit
271sample_8any1755permit
272sample_7any1024permit
273sample_8any1024permit
274sample_7any80permit
275sample_7any1755permit
276sample_7any554permit
277sample_8any554permit
278sample_8any1755permit
280sample_5510.0.0.91/32sample_56permit
28110.0.0.182/3222.119.64.11/3221permit
28210.0.0.182/3210.0.0.102/3221permit
28310.0.0.170/32any9008:9009permit
28710.0.0.164/32sample_57mask-requestpermit
29810.0.10.8/3010.0.0.21/32161:162permit
299sample_59sample_60161permit
30010.0.0.164/3210.0.0.21/32161permit
301sample_61sample_62443permit
30210.0.0.164/3210.0.0.22/32161permit
303sample_63sample_64sample_65permit
31010.0.0.159/3210.0.0.110/32443permit
31110.0.0.167/3210.0.0.110/32443permit
317sample_70any53permit
318sample_71sample_732002:2010permit
334sample_7810.0.0.64/26sample_79permit
34110.0.8.94/32anyanypermit
342sample_24sample_84sample_85permit
34410.0.0.210/32sample_88sample_89permit
35410.0.0.0/810.0.0.24/3280permit
35910.0.2.71/3210.0.0.102/32161permit
36210.0.2.72/3210.0.0.102/32162permit
36310.0.12.13/3210.0.0.102/3280permit
36410.0.12.13/3210.0.0.102/3210198permit
36510.0.12.13/3210.0.0.102/3210319permit
36610.0.0.102/3210.0.0.71/32161permit
36710.0.0.102/3210.0.0.71/32162permit
36810.0.0.102/3210.0.0.72/32161permit
36910.0.0.102/3210.0.0.72/32162permit
37010.0.0.102/3210.0.12.13/3280permit
37110.0.0.102/3210.0.12.13/3210198permit
37210.0.0.102/3210.0.12.13/3210319permit
37310.0.0.162/3210.0.0.41/3255011:55012permit
37410.0.0.162/32sample_10155011:55012permit
375sample_10210.0.39.195/327777permit
37610.0.0.188/3222.118.154.29/3280permit
377sample_4any443permit
37810.255.255.67/32sample_457001permit
38210.0.239.7/32anysample_103permit
38310.0.239.7/32anysample_104permit
384any10.0.239.7/32sample_104permit
385anysample_1sample_107permit
386anysample_1sample_106permit
394sample_108sample_109636permit
400sample_108sample_109636permit
406sample_28sample_1145555permit
409sample_115any80permit
41010.0.0.70/3210.0.9.210/32anypermit


Results of redundant analysis

The first policy is a subset of the second one


IDSource HostsDestination HostsServicesAction
37sample_75sample_761645:1646permit
124sample_72sample_731645:1646permit


IDSource HostsDestination HostsServicesAction
38sample_75sample_76radius:radius-acctpermit
125sample_72sample_73radius:radius-acctpermit


IDSource HostsDestination HostsServicesAction
94sample_4910.0.0.164/32group_94permit
9710.0.6.54/3210.0.0.164/32mask-replypermit


IDSource HostsDestination HostsServicesAction
37sample_75sample_761645:1646permit
124sample_72sample_731645:1646permit


IDSource HostsDestination HostsServicesAction
31210.0.0.176/3210.0.0.110/32443permit
325sample_7710.0.0.110/32443permit


IDSource HostsDestination HostsServicesAction
307sample_6810.0.0.24/3280permit
35710.0.0.0/810.0.0.24/3280permit


Results of group analysis

The following policies can be grouped together


IDSource HostsDestination HostsServicesAction
30anysample_22group_30permit
88anysample_2281permit
89anysample_22449permit


IDSource HostsDestination HostsServicesAction
3910.0.0.225/3210.0.0.67/32group_39permit
5510.0.0.225/3210.0.0.67/32radiuspermit


IDSource HostsDestination HostsServicesAction
40any10.0.0.20/32group_40permit
42any10.0.0.20/32443permit


IDSource HostsDestination HostsServicesAction
90any10.0.0.110/32group_90permit
91any10.0.0.110/3280permit
126any10.0.0.110/3211001permit


IDSource HostsDestination HostsServicesAction
92any10.0.0.91/32group_92permit
93any10.0.0.91/32443permit


IDSource HostsDestination HostsServicesAction
94sample_4910.0.0.164/32group_94permit
95sample_4910.0.0.164/32echo-replypermit


IDSource HostsDestination HostsServicesAction
183sample_7anygroup_183permit
308sample_7any443permit


IDSource HostsDestination HostsServicesAction
185sample_8anygroup_185permit
279sample_8any80permit
309sample_8any443permit


IDSource HostsDestination HostsServicesAction
19410.0.0.25/32anygroup_194permit
19510.0.0.25/32any80permit


IDSource HostsDestination HostsServicesAction
26210.0.0.164/32sample_49group_262permit
26310.0.0.164/32sample_49mask-replypermit


IDSource HostsDestination HostsServicesAction
28410.0.0.163/32anygroup_284permit
28510.0.0.163/32any9009permit


IDSource HostsDestination HostsServicesAction
28810.0.0.164/32sample_57group_288permit
28910.0.0.164/32sample_57echopermit


IDSource HostsDestination HostsServicesAction
29010.0.0.164/32sample_57group_290permit
29110.0.0.164/32sample_571050:1075permit


IDSource HostsDestination HostsServicesAction
29510.0.10.8/3010.0.0.22/32group_295permit
29610.0.10.8/3010.0.0.22/3223permit


IDSource HostsDestination HostsServicesAction
327sample_78sample_8group_327permit
330sample_78sample_822permit


IDSource HostsDestination HostsServicesAction
328sample_78sample_7group_328permit
331sample_78sample_723permit
332sample_78sample_78080permit


IDSource HostsDestination HostsServicesAction
350sample_99sample_98group_350permit
351sample_99sample_98echopermit


IDSource HostsDestination HostsServicesAction
352sample_98sample_99group_352permit
353sample_98sample_99echopermit


IDSource HostsDestination HostsServicesAction
40410.0.0.186/3210.0.0.70/32group_404permit
40510.0.0.186/3210.0.0.70/32sample_17permit


Results of objects analysis

The following objects can be dropped

Objects
no object-group service sample_104
no object-group service sample_106
no object-group service sample_118
no object-group service sample_119
no object-group service sample_44
no object-group service sample_50
no object-group service sample_54
no object-group service sample_56
no object-group service sample_67
no object-group service sample_80
no object-group service sample_89
no object-group network sample_101
no object-group network sample_102
no object-group network sample_115
no object-group network sample_116
no object-group network sample_117
no object-group network sample_45
no object-group network sample_47
no object-group network sample_48
no object-group network sample_51
no object-group network sample_52
no object-group network sample_53
no object-group network sample_55
no object-group network sample_59
no object-group network sample_60
no object-group network sample_61
no object-group network sample_62
no object-group network sample_66
no object-group network sample_68
no object-group network sample_75
no object-group network sample_76
no object-group network sample_88
no object-group network sample_96


Results of undeclared source host analysis

The following are the rules in which source hosts are not declared in the configuration



Results of undeclared destination host analysis

The following are the rules in which destination hosts are not declared in the configuration


IDSource HostsDestination HostsServicesAction
5any4000anydeny
21110.0.0.193/3210.0.135/3264020:64021permit
21210.0.0.194/3210.0.135/3264020:64021permit


Results of undeclared services analysis

The following are the rules in which services are not declared in the configuration


IDSource HostsDestination HostsServicesAction
1anyany42deny
2anyany42deny
3anyany5554deny
4anyany9996deny
7anyany1434deny
10sample_12/23sample_180permit
11anysample_280permit
12anysample_1925permit
13anysample_1825permit
14anysample_3825permit
15any10.0.0.154/3225permit
16anysample_1021permit
17sample_12/23sample_98080permit
18any10.0.0.66/3253permit
19any10.0.0.66/3253permit
20any10.0.0.67/3253permit
21any10.0.0.67/3253permit
23anysample_380permit
29sample_20sample_180permit
30anysample_22group_30permit
32sample_16/2210.0.0.78/3253permit
34sample_16/2210.0.0.77/3253permit
35sample_16/2210.0.0.77/3253permit
36sample_16/24sample_21162permit
3910.0.0.225/3210.0.0.67/32group_39permit
40any10.0.0.20/32group_40permit
43any10.0.0.25/32443permit
44any10.0.0.19/32echopermit
45any10.0.0.21/32echopermit
4810.0.0.20/32any80permit
4910.0.0.25/32any80permit
56any10.0.0.73/3225permit
58171.68.227.106/32sample_3323permit
5910.0.0.225/32sample_3323permit
62sample_4610.0.0.66/32radiuspermit
63sample_4610.0.0.67/32radiuspermit
6410.30.14.130/32sample_98080:8081permit
6510.0.19.2/32sample_98080:8081permit
8022.247.15.77/3210.0.0.168/3222permit
90any10.0.0.110/32group_90permit
92any10.0.0.91/32group_92permit
94sample_4910.0.0.164/32group_94permit
116sample_5710.0.0.164/32echo-replypermit
11710.0.0.226/3210.0.0.185/322055permit
121any10.0.0.24/3280permit
123anysample_58443permit
125sample_72sample_73radius:radius-acctpermit
13310.0.0.189/3210.0.3.92/3221permit
13610.0.0.188/3222.118.154.29/3280permit
137anysample_4443permit
140any10.0.0.116/32443permit
14110.0.0.253/32sample_241645:1656permit
14210.0.0.253/32sample_281645:1656permit
145any10.0.0.26/32443permit
146sample_11110.0.0.12/32636permit
147sample_11110.0.0.12/32636permit
150any10.0.0.101/3225permit
15110.0.0.12/32sample_111636permit
153sample_108sample_109636permit
154sample_108sample_109636permit
161sample_37any53permit
162sample_37any53permit
16610.0.0.145/32sample_438080permit
16710.0.0.66/32any53permit
172sample_38any25permit
17410.0.0.145/3210.0.3.140/328080permit
183sample_7anygroup_183permit
185sample_8anygroup_185permit
186sample_29sample_3021permit
18710.0.0.139/32sample_3021permit
190any10.0.0.20/32443permit
19410.0.0.25/32anygroup_194permit
21110.0.0.193/3210.0.135/3264020:64021permit
21210.0.0.194/3210.0.135/3264020:64021permit
21310.0.0.157/3210.0.0.137/3221permit
24510.0.0.166/3210.0.0.137/3221permit
24610.0.0.143/3210.0.0.84/3221permit
24710.0.0.164/3210.0.0.51/3221permit
24910.0.0.226/3210.0.0.66/321645permit
26210.0.0.164/32sample_49group_262permit
267sample_8any5005permit
268sample_7any5000permit
28410.0.0.163/32anygroup_284permit
28610.0.0.163/32sample_879006permit
28810.0.0.164/32sample_57group_288permit
29010.0.0.164/32sample_57group_290permit
29210.0.0.185/3210.0.0.226/32161permit
29310.0.10.8/3010.0.0.22/32echopermit
29410.0.10.8/3010.0.0.21/32echopermit
29510.0.10.8/3010.0.0.22/32group_295permit
29710.0.10.8/3010.0.0.21/3223permit
30510.0.3.156/3210.0.0.22/3221permit
30610.0.0.156/3210.0.0.22/3221permit
31310.0.0.110/3210.0.0.159/3255012permit
314sample_69sample_7053permit
315sample_69sample_7053permit
316sample_70any53permit
319sample_72sample_731645:1646permit
320sample_72sample_73radius:radius-acctpermit
321sample_71sample_732002:2010permit
322sample_73sample_74389permit
323sample_73sample_74389permit
324sample_7710.0.0.162/32443permit
325sample_7710.0.0.110/32443permit
327sample_78sample_8group_327permit
328sample_78sample_7group_328permit
32910.0.0.96/3210.0.137.194/3221permit
333sample_8110.0.39.195/327777permit
33610.0.0.23/3210.0.0.1/3220:21permit
337any10.0.0.110/3211001permit
339any10.0.0.110/3211001permit
34910.0.0.187/3213.130.50.253/325151permit
350sample_99sample_98group_350permit
352sample_98sample_99group_352permit
35710.0.0.0/810.0.0.24/3280permit
35810.245.1.5/3210.0.0.102/32echo-replypermit
36010.0.2.71/3210.0.0.102/32162permit
36110.0.2.72/3210.0.0.102/32161permit
37910.255.255.69/32sample_457001permit
380sample_2410.0.0.253/321645:1656permit
381sample_2810.0.0.253/321645:1656permit
387sample_10522.118.154.29/3280permit
38910.0.7.223/3213.130.50.253/325151permit
390sample_108sample_109626permit
391sample_108sample_109626permit
392sample_110sample_285555permit
393sample_110sample_285555permit
39810.0.0.101/32any25permit
403sample_28sample_1145555permit
40410.0.0.186/3210.0.0.70/32group_404permit

All hosts, objects, groups, services are purely fictitious.