Wallsight
PAN-OS CONFIGURATION AUDIT
How it works Report Privacy Roadmap Try the demo
FOR PALO ALTO NETWORKS FIREWALLS
See the gaps in your firewall before attackers do.
Drop your configuration file and every rule and management setting is checked, one by one. In seconds you have a summary your manager can read and step-by-step fixes your engineer can apply.
Nothing is sent to the internet PAN-OS 10 · 11 · 12 Firewall · Panorama · TSF
ILLUSTRATION · SAMPLE DATA
1<security><rules>
2  <entry name="allow-any">
3    <source>any</source>
4    <destination>any</destination>
5    <application>any</application>
6    <action>allow</action>
7  </entry>
8</rules></security>
9<system>
10  <service>
11    <disable-telnet>no</disable-telnet>
12  </service>
OVERALL SCORE
0
/ 100
CRITICAL
An allow-everything rule
HIGH
Telnet open on management
MEDIUM
No decryption rule
How it works
No install · no account · nothing leaves your network
1
running-config.xml · ts.tgz
Drop the file
Drag in the running configuration exported from your firewall, a Panorama export or a tech support file. The type is detected automatically.
2
j.smith
Choose what to hide
Passwords, user names, IP addresses and device names are replaced with placeholders in the report, so you can share it with a client or your team.
3
Get the report
A single-file report: an overall score, findings by severity and, for each finding, the first step, estimated effort and owner.
TWO READERS, ONE REPORT
Managers see why it matters. Engineers see where to click.
The executive summary explains the risk in plain language and ranks what to fix first. The technical tab gives each finding its evidence, the first step as a PAN-OS menu path, and the estimated effort.
FIX THESE FIRST · SAMPLE
1
Narrow the allow-everything rule
Source, destination and application are unrestricted.
~half day
2
Turn off Telnet and HTTP on management
Passwords cross the network unencrypted.
~5 min
3
Restrict management to permitted IPs
The management port is reachable from any network.
~15 min
CONSULTANTS AND MSSPS
Deliver a client audit in one sitting instead of days.
IN-HOUSE SECURITY TEAMS
Compare the configuration before and after a change against the same checks.
MANAGERS
See the risk as one score and three priorities, without the jargon.
PRIVACY
Your configuration stays on-premises. Offline, no cloud.
The analysis runs offline, on-premises — on a workstation, a server or an isolated network — and nothing goes to any cloud; no AI is involved. The file is held in memory only and discarded once the report is written. The checks are fixed rules that give the same result every time.
Try the live demo Book a demo
No install, no account
Works without an internet connection
The file is cleared from memory after analysis
Sensitive data is masked before you share
ROADMAP
What we are building next
This list shows direction, not dates: each item lands only when it works well enough to trust.
Next End-of-life check
Compare the PAN-OS software and the hardware model with the official end-of-life dates.
Next Vulnerability exposure report
PAN-OS security advisories of the last six months, checked separately against the software version and against each advisory's required configuration for exposure.
Next Policy and object hygiene
Unused and duplicate objects, empty groups, rules without tags or descriptions.
Next Official references
Links to Palo Alto Networks documentation and knowledge base articles for every recommendation.
Later Compliance mapping
Every finding mapped to the CIS Palo Alto Networks Benchmark, PCI DSS, ISO 27001 and NIST controls, with a compliance summary in the report.
Later Change and drift analysis
Compare two configurations or tech support files: what changed, whether risk went up or down, and the score trend over time.
Later Panorama fleet audit
All device groups and managed firewalls in one report, with the riskiest devices and shared problems first.
Later Remediation commands
Reviewable PAN-OS CLI / set commands for each finding, never applied automatically.
Later Other firewall vendors
The same local audit for other firewall vendors.
Wallsight · PAN-OS configuration audit · runs locally Findings must be reviewed and signed off by a qualified engineer.