The reports you can run to look for redundant ACL’s in the firewalls, and the policy trace and review. It also allows you to tie to multiple domains so that the administrators for the FireMon servers do not have to deal with the hassle of making 'view only' accounts. You can also use the Insight function to keep records of the ACL’s. Instead of filling up the firewall with remark statements that could lose their position, you can leave all the information in the FireMon server, and you can tie in ticket information. It also allows you to put an expiration date on that ACL so that you can always remove unneeded exceptions.
Improvements to My Organization
It improved performance of the organization, as instead of going line through line of the firewall, we were able to quickly find IP addresses or services using Firemon.
Room for Improvement
I believe their network maps have a lot of room for improvement. I think they should allow more customization.
Use of Solution
I have only worked on this product for a year.
We have not had any issues with stability.
My organization only used FireMon for Cisco ASA products, so I am not sure if it works with other firewalls but it does support other vendors.
Customer Service and Technical Support
Great, they hold free WebEx sessions for additional training on FireMon. Technical Support
They're extremely responsive and experienced on the product.
We did not have a previous solution.
Using this product allows firewall administrators to quickly find a problem with their firewall configurations. It allows the administrators to also look for open services that should not be allowed. One of the most useful features is the ability to use policy trace. If you work in an environment with multiple tiered firewalls you can look at exactly what ACL’s the traffic is going through on each firewall without having to have permission to those firewalls.
It is a smart move to make and makes the administration and troubleshooting of ACL problems clear.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Jul 20 2015