SAMPLE DATA This report was generated by Wallsight from a fictional demo firewall. Names and addresses are masked.
Wallsight · Configuration audit report

Firewall security assessment

Firewall · PAN-OS 11.1.x · 52 findings
Analysed locally; the configuration never left this machine

Overall score

23/ 100

High risk. 4 critical findings leave the device exposed until they are fixed.

Score 23/100 (high risk) overall. 4 Critical, 3 High, 22 Medium and 23 Low findings were found. Fix first: an allow-everything rule, insecure services open to the internet and cleartext management access.

How the score was calculated

Start at 100 points. Each level has a weight (Critical 12, High 5, Medium 2, Low 0.5) that is multiplied by the number of findings; every additional finding at the same level counts 90% as much as the previous one. Total deduction 77.4, result 23/100.

LevelCountWeightDeducted
Critical412.041.3
High35.013.6
Medium222.018.0
Low230.54.6

Total deducted: 77.4

Findings by severity

  • 4 Critical
  • 3 High
  • 22 Medium
  • 23 Low

Fix these first

  1. 1
    An allow-everything rule
    This rule allows anyone to access any internal resource, making a breach trivial if a single password is stolen.
    ~half day
  2. 2
    Insecure services open to the internet
    Exposing management ports like SSH or RDP to the internet allows attackers to attempt brute-force logins to your servers.
    ~15 min
  3. 3
    Cleartext management access
    Enabling HTTP or Telnet sends management credentials in plain text, allowing them to be stolen by anyone on the path.
    ~15 min