Results of analysis carried out for:

FirewallHatSecurity.com-PIX-demo1
TypeCisco PIX
Date7/2/2008 10:58:17 PM

Statistics on the analysis:

Rules categoryNumber droppedPercentage
Log analysis 200 48.66 %
Redundant 5 1.216 %
Grouped 18 4.379 %
Unused objects 0

Results of log analysis

The following policies can be dropped based on log analysis


IDSource HostsDestination HostsServicesAction
8anyAnywhere6129deny
24anyedirectory180permit
31dialup/24inetlog02161permit
33dialup/2222.118.128.78/3253permit
41any22.118.128.25/3280permit
5022.118.128.20/32Anywhere443permit
5122.118.128.25/32Anywhere443permit
52ABCNetBSC8080permit
53any22.118.128.152/3280permit
54any22.118.128.152/32443permit
57anysymantec125permit
60any22.118.128.95/3280permit
61ipass22.118.128.158/32577permit
66195.149.45.5/3222.118.128.68/3223permit
6722.138.47.100/3222.118.128.68/32anypermit
6822.138.47.100/32cache1-outanypermit
6922.118.136.198/3222.118.128.68/32anypermit
7022.118.136.198/32cache1-outanypermit
7122.26.63.45/3222.118.128.68/32anypermit
7322.118.128.225/3222.118.128.66/32radius:radius-acctpermit
7422.118.128.225/3222.118.128.67/32radius:radius-acctpermit
7564.104.205.63/32cisco-tac23permit
76ebill172.20.238.77/321521permit
77ebill172.20.238.77/321521permit
7822.118.128.224/28inetlog02515permit
7922.247.15.77/3222.118.128.169/3222permit
8122.118.128.226/3222.118.128.66/32radiuspermit
8222.118.128.226/3222.118.128.66/32radius-acctpermit
8322.234.153.202/32Anywhereanydeny
8422.118.128.226/3222.118.128.67/32radiuspermit
8522.118.128.226/3222.118.128.67/32radius-acctpermit
86any22.118.128.92/3281permit
87any22.118.128.92/32449permit
9822.118.136.54/3222.118.128.164/32echo-replypermit
9922.118.136.198/3222.118.128.164/32mask-replypermit
10022.118.136.198/3222.118.128.164/32echo-replypermit
10122.118.133.140/3222.118.128.164/32mask-replypermit
10222.118.133.140/3222.118.128.164/32echo-replypermit
10322.118.133.133/3222.118.128.164/32mask-replypermit
10422.118.133.133/3222.118.128.164/32echo-replypermit
105ABCNetP22.118.128.164/32mask-replypermit
106ABCNetP22.118.128.164/32echo-replypermit
10722.118.133.137/3222.118.128.164/32mask-replypermit
10822.118.133.137/3222.118.128.164/32echo-replypermit
10922.247.15.77/3222.118.128.168/3223permit
11022.247.15.77/3222.118.128.168/3221permit
11122.247.15.77/3222.118.128.169/3223permit
11222.247.15.77/3222.118.128.169/3221permit
113anycache1-out6970:7170permit
114anycache2-out6970:7170permit
115scr05-01-1685_sscr05-01-1685_dscr05-01-1685_ppermit
12022.135.137.194/3222.135.137.194/3220permit
122any22.118.128.24/3280permit
135escr7069_dsymantec3escr7069_p1permit
138intranetAnywhereescr8793_p1permit
143anyintranetescr8931_p2permit
144anyintranetescr8931_p1permit
15210.33.16.12/32escr8942_d63permit
158anyAnywhereanypermit
159DNS2Anywhere53permit
160DNS2Anywhere53permit
163WASAnywhereanypermit
164WAPAnywhereanypermit
16522.118.128.66/32Anywhere53permit
16822.118.128.67/32Anywhere53permit
16922.118.128.67/32Anywhere53permit
170HASimc01Anywhere25permit
171HASimc02Anywhere25permit
17322.118.128.154/32Anywhere25permit
17522.118.128.143/32ABCNetP8080permit
176wireless-BBAnywhereanypermit
177pptpAnywherepptppermit
178pptpAnywhereanypermit
180pptp2Anywhereanypermit
182cache2-outAnywhere8080permit
184cache1-outAnywhere21permit
189any22.118.128.20/3280permit
191any22.118.128.25/32443permit
192any22.118.128.25/3280permit
19322.118.128.20/32Anywhere443permit
19622.118.128.20/32Anywhere80permit
19722.118.128.136/32ftp.sun.co.uk/3221permit
19822.118.128.136/32ftp.hostnet.cz/3221permit
19922.118.128.149/32ftp.sun.co.uk/3221permit
20022.118.128.149/32ftp.hostnet.cz/3221permit
20122.118.128.151/32ftp.sun.co.uk/3221permit
20222.118.128.151/32ftp.hostnet.cz/3221permit
20322.118.128.153/32Cisco_FTP21permit
20422.118.128.76/32Anywhere21permit
20522.118.128.76/32Anywhere8080permit
20622.118.128.76/32Anywhere80permit
20722.118.128.73/32Anywhere25permit
208symantec1Anywhere25permit
20922.118.128.155/32195.229.49.177/32443permit
21022.118.128.155/32195.229.49.177/328080permit
21422.118.128.157/32192.100.121.12/328080permit
21522.118.128.157/32192.100.121.12/321494permit
21622.118.128.157/32192.100.121.12/321604permit
21722.118.128.68/3222.138.47.100/32anypermit
218cache1-out22.138.47.100/32anypermit
21922.118.128.68/3222.138.47.100/32anypermit
220cache1-out22.138.47.100/32anypermit
221IntGroupHost192.168.219.53/32443permit
222IntGroupHost192.135.250.12/32443permit
223IntGroupHost64.103.36.134/32443permit
224IntGroupHost192.135.250.12/3221permit
22522.118.128.158/3213.86.133.55/32anypermit
22610.32.88.210/3222.162.134.90/329009permit
22722.118.128.100/3222.138.47.100/328080permit
22822.118.128.155/32192.229.49.177/328080permit
22922.118.128.155/32192.229.49.177/32443permit
2308.2.250.250/3222.118.128.68/3223permit
2318.2.250.250/3222.118.128.68/3223permit
2328.2.250.250/3222.118.128.68/328081permit
2338.2.250.250/3222.118.128.68/328081permit
2348.2.250.250/3222.118.128.69/3223permit
2358.2.250.250/3222.118.128.69/3223permit
2368.2.250.250/3222.118.128.69/328081permit
2378.2.250.250/3222.118.128.69/328081permit
238172.20.238.77/32ebill1521permit
239172.20.238.77/32ebill1521permit
24022.118.128.162/32SCR1588-87_danypermit
24122.118.128.162/32SCR1588-87_disakmppermit
24222.118.128.162/32SCR1588-87_d10000permit
24322.118.128.162/32192.245.235.140/32anypermit
24422.118.128.165/32192.6.126.144/32443permit
24810.32.15.235/32Anywhereanydeny
25022.118.128.226/3222.118.128.66/321646permit
25122.118.128.226/3222.118.128.67/321646permit
25222.118.128.226/3222.118.128.67/321645permit
25322.118.128.163/3222.118.133.133/328080permit
25422.118.128.163/3222.118.133.137/328080permit
25522.118.128.163/32ABCNetP8080permit
25622.118.128.163/3222.118.133.140/328080permit
25722.118.128.164/32scr2160_dechopermit
25822.118.128.164/32scr2160_dmask-requestpermit
25922.118.128.91/32Anywhere80permit
26022.118.128.91/32Anywhere443permit
26122.118.128.108/32207.46.197.119/3280permit
264cache1-outAnywhere2000:2001permit
265cache2-outAnywhere2000:2001permit
266cache1-outAnywhere5005permit
269cache2-outAnywhere5000permit
270cache1-outAnywhere1755permit
271cache2-outAnywhere1755permit
272cache1-outAnywhere1024permit
273cache2-outAnywhere1024permit
274cache1-outAnywhere80permit
275cache1-outAnywhere1755permit
276cache1-outAnywhere554permit
277cache2-outAnywhere554permit
278cache2-outAnywhere1755permit
280scr05-01-1581_s22.118.128.91/32scr05-01-1581_ppermit
28122.118.128.182/3222.119.64.11/3221permit
28222.118.128.182/3222.93.192.102/3221permit
28322.118.128.170/32Anywhere9008:9009permit
28722.118.128.164/32scr2160mask-requestpermit
298172.20.10.8/3022.118.128.21/32161:162permit
299escr2129_sescr2129_d161permit
30022.118.128.164/3222.118.128.21/32161permit
301escr2689_sescr2689_d443permit
30222.118.128.164/3222.118.128.22/32161permit
303escr2812_sescr2812_descr2812_ppermit
31022.118.128.159/3212.151.162.110/32443permit
31122.118.128.167/3212.151.162.110/32443permit
317escr-4463_dAnywhere53permit
318escr-4466_sescr-4466_d2002:2010permit
334escr5723_s22.118.128.64/26escr5723_ppermit
34110.32.8.94/32Anywhereanypermit
342symantec3escr7069_descr7069_ppermit
34422.32.88.210/32escr7197_descr7197_ppermit
354172.0.0.0/822.118.128.24/3280permit
35910.32.2.71/3222.118.128.102/32161permit
36210.32.2.72/3222.118.128.102/32162permit
363172.20.12.13/3222.118.128.102/3280permit
364172.20.12.13/3222.118.128.102/3210198permit
365172.20.12.13/3222.118.128.102/3210319permit
36622.118.128.102/3210.32.0.71/32161permit
36722.118.128.102/3210.32.0.71/32162permit
36822.118.128.102/3210.32.0.72/32161permit
36922.118.128.102/3210.32.0.72/32162permit
37022.118.128.102/32172.20.12.13/3280permit
37122.118.128.102/32172.20.12.13/3210198permit
37222.118.128.102/32172.20.12.13/3210319permit
37312.151.162.162/3222.118.129.41/3255011:55012permit
37412.151.162.162/32escr8241_d55011:55012permit
375escr8384_s172.20.39.195/327777permit
37622.118.128.188/3222.118.154.29/3280permit
377AymaAnywhere443permit
37810.255.255.67/32Ayma57001permit
382172.20.239.7/32Anywhereescr8764_ppermit
383172.20.239.7/32Anywhereescr8764_p1permit
384any172.20.239.7/32escr8764_p1permit
385anyintranetescr8793_p3permit
386anyintranetescr8793_p1permit
394escr8784_sescr8784_d636permit
400escr8784_sescr8784_d636permit
406symantec4escr9020_d5555permit
409escr9332_sAnywhere80permit
410193.110.54.70/3210.32.9.210/32anypermit

Results of shadow analysis

The first and second policies in each set match the same traffic, but have the opposite actions


IDSource HostsDestination HostsServicesAction
7222.26.63.45/32cache1-outanypermit
157anyAnywhereanydeny


IDSource HostsDestination HostsServicesAction
11822.118.128.226/3222.118.128.185/32anypermit
157anyAnywhereanydeny


IDSource HostsDestination HostsServicesAction
11922.118.128.225/3222.118.128.185/32anypermit
157anyAnywhereanydeny


IDSource HostsDestination HostsServicesAction
155any22.118.128.102/32anypermit
157anyAnywhereanydeny


IDSource HostsDestination HostsServicesAction
181inetlog02Anywhereanypermit
411anyAnywhereanydeny


IDSource HostsDestination HostsServicesAction
15622.118.128.102/32Anywhereanypermit
157anyAnywhereanydeny


IDSource HostsDestination HostsServicesAction
188Ahme22.118.128.225/32anypermit
411anyAnywhereanydeny


IDSource HostsDestination HostsServicesAction
34010.32.8.90/32Anywhereanypermit
411anyAnywhereanydeny


IDSource HostsDestination HostsServicesAction
401any22.118.128.102/32anypermit
411anyAnywhereanydeny


IDSource HostsDestination HostsServicesAction
40722.118.128.186/32193.110.54.70/32anypermit
411anyAnywhereanydeny


IDSource HostsDestination HostsServicesAction
40222.118.128.102/32Anywhereanypermit
411anyAnywhereanydeny

Results of redundant analysis

The first policy is a subset of the second one


IDSource HostsDestination HostsServicesAction
37escr4466_sescr4466_d1645:1646permit
124escr-4466_s1escr-4466_d1645:1646permit


IDSource HostsDestination HostsServicesAction
38escr4466_sescr4466_dradius:radius-acctpermit
125escr-4466_s1escr-4466_dradius:radius-acctpermit


IDSource HostsDestination HostsServicesAction
94scr2160_d22.118.128.164/32mask-replypermit
9722.118.136.54/3222.118.128.164/32mask-replypermit


IDSource HostsDestination HostsServicesAction
37escr4466_sescr4466_d1645:1646permit
124escr-4466_s1escr-4466_d1645:1646permit


IDSource HostsDestination HostsServicesAction
31222.118.128.176/3212.151.162.110/32443permit
325escr4979_s12.151.162.110/32443permit

Results of group analysis

The following policies can be grouped together


IDSource HostsDestination HostsServicesAction
30anyebillgroup_30permit
88anyebill81permit
89anyebill449permit


IDSource HostsDestination HostsServicesAction
3922.118.128.225/3222.118.128.67/32group_39permit
5522.118.128.225/3222.118.128.67/32radiuspermit


IDSource HostsDestination HostsServicesAction
40any22.118.128.20/32group_40permit
42any22.118.128.20/32443permit


IDSource HostsDestination HostsServicesAction
90any22.118.128.110/32group_90permit
91any22.118.128.110/3280permit
126any22.118.128.110/3211001permit


IDSource HostsDestination HostsServicesAction
92any22.118.128.91/32group_92permit
93any22.118.128.91/32443permit


IDSource HostsDestination HostsServicesAction
183cache1-outAnywheregroup_183permit
308cache1-outAnywhere443permit


IDSource HostsDestination HostsServicesAction
185cache2-outAnywheregroup_185permit
279cache2-outAnywhere80permit
309cache2-outAnywhere443permit


IDSource HostsDestination HostsServicesAction
19422.118.128.25/32Anywheregroup_194permit
19522.118.128.25/32Anywhere80permit


IDSource HostsDestination HostsServicesAction
28422.118.128.163/32Anywheregroup_284permit
28522.118.128.163/32Anywhere9009permit


IDSource HostsDestination HostsServicesAction
29022.118.128.164/32scr2160group_290permit
29122.118.128.164/32scr21601050:1075permit


IDSource HostsDestination HostsServicesAction
295172.20.10.8/3022.118.128.22/32group_295permit
296172.20.10.8/3022.118.128.22/3223permit


IDSource HostsDestination HostsServicesAction
327escr5723_scache2-outgroup_327permit
330escr5723_scache2-out22permit


IDSource HostsDestination HostsServicesAction
328escr5723_scache1-outgroup_328permit
331escr5723_scache1-out23permit
332escr5723_scache1-out8080permit


IDSource HostsDestination HostsServicesAction
40422.118.128.186/32193.110.54.70/32group_404permit
40522.118.128.186/32193.110.54.70/32pptppermit

Results of objects analysis

The following objects can be dropped

Objects
no object-group service escr3240_p
no object-group service escr5723_p1
no object-group service escr7197_p
no object-group service escr8764_p1
no object-group service escr8793_p1
no object-group service escr9313_p
no object-group service escr9313_p1
no object-group service Internet-MIS
no object-group service scr05-01-1581_p
no object-group service scr05-01-1685_p
no object-group service scr2160_p
no object-group network escr2129_d
no object-group network escr2129_s
no object-group network escr2689_d
no object-group network escr2689_s
no object-group network escr3240_d
no object-group network escr4466_d
no object-group network escr4466_s
no object-group network escr7197_d
no object-group network escr7880_s
no object-group network escr8241_d
no object-group network escr8384_s
no object-group network escr9313_d
no object-group network escr9313_s
no object-group network escr9332_s
no object-group network ipass
no object-group network scr05-01-1581_s
no object-group network scr05-01-1685_d
no object-group network scr05-01-1685_s
no object-group network scr1444_d
no object-group network SCR1588-87_d
no object-group network tada_d

Results of analysis carried out for:

FirewallHatSecurity.com-PIX-demo1
TypeCisco PIX
Date7/2/2008 11:04:44 PM

Statistics on the analysis:

Rules categoryNumber droppedPercentage
Log analysis 200 48.66 %
Redundant 5 1.216 %
Grouped 18 4.379 %
Unused objects 31

Results of redundant analysis

The first policy is a subset of the second one