See exploitable paths
Connect isolated configuration issues into the routes an attacker could actually use — WAN exposure, missing inspection, and segmentation gaps chained into one map.
Firewall exposure management
CRWLR finds exploitable paths hidden in FortiGate, Palo Alto, Sophos, Check Point, and Cisco ASA configurations — then gives your team prioritized CLI fixes and audit-ready evidence.
2 free scans · no credit card · results in ~60s · see pricing
Policy 42 creates a direct path from the internet to the internal network without inspection.
set ips-sensor "default"Built for the firewalls your network already runs
One clear view of exposure
Built for security leaders who need evidence and network engineers who need exact remediation — from the same scan.
Connect isolated configuration issues into the routes an attacker could actually use — WAN exposure, missing inspection, and segmentation gaps chained into one map.
Every finding ships with vendor-specific CLI remediation and the context behind the change, ready to paste into FortiGate, PAN-OS, SFOS, Check Point, or ASA.
Turn every scan into measurable posture history, acknowledged-risk tracking, and audit-ready evidence mapped to the controls your auditors check.
Compliance
Every finding cites the controls your auditors check. CRWLR maps results to the CIS Benchmarks for your vendor, PCI DSS Requirement 1, and NIST 800-41 firewall policy guidelines — so a scan doubles as audit-ready evidence for your next rule review.
Built for sensitive infrastructure
Configs are parsed in memory and never written to disk or database — only the normalized findings are stored. Optional client-side sanitizer strips secrets before anything leaves your machine.
For security teams
Attack-path maps, firmware CVE correlation, and per-policy grading — with paste-ready CLI remediation your network team can act on the same day.
Run the sample audit →For MSPs
Per-client scoring, bulk import, scheduled re-scans, role-based team access, and exportable evidence packages for client compliance reporting.
See MSP pricing →A firewall configuration audit is a systematic review of your firewall rules, policies, and system settings to find security gaps, misconfigurations, and compliance violations. CRWLR automates this process — upload your config file and get a security posture score with prioritized findings in under 60 seconds.
CRWLR supports Fortinet FortiGate (.conf), Palo Alto Networks (XML), Sophos XG/XGS (XML or PostgreSQL dump), Check Point R80+ (JSON from mgmt_cli), and Cisco ASA (show running-config). Each vendor gets tailored remediation commands you can paste directly into your firewall CLI.
Attack path analysis maps how multiple individual misconfigurations can chain together into an exploitable route through your network. For example, an overly permissive WAN rule combined with missing SSL inspection and no IPS profile creates a path for data exfiltration that no single finding would reveal on its own.
No. Your raw config file is parsed entirely in memory and never written to disk or database. This is an architecture-level guarantee, not just a policy. Only the normalized analysis results (findings, scores, remediation) are stored — never the original configuration.
PCI DSS v4.0 Req 1.2.7 requires firewall rule reviews every 6 months. Many frameworks and cyber-insurers also expect more frequent reviews. For organizations with frequent changes, monthly automated scans catch configuration drift before it becomes a compliance gap or security risk.
CRWLR maps findings to CIS Benchmarks (FortiGate, Palo Alto, Sophos), PCI DSS Requirement 1 (network security controls), and NIST 800-41 (firewall policy guidelines). Each finding shows which compliance controls it affects.
Yes. CRWLR supports multi-tenant fleet management — manage all your client firewalls from one dashboard with per-client scoring, bulk import via ZIP, and exportable audit evidence packages for compliance reporting.
CRWLR detects your exact firmware version and cross-references it against CISA Known Exploited Vulnerabilities (KEV), NVD, and vendor-specific PSIRT feeds. It only alerts on CVEs for features actually enabled on your firewall — no noise from vulnerabilities in disabled modules.
Export your firewall configuration (FortiGate .conf, Palo Alto or Sophos XML, Check Point JSON or Gaia clish, or Cisco ASA show running-config) and analyze it for overly permissive rules, missing security profiles, exposed management interfaces, weak VPN crypto, zone-segmentation gaps, and firmware CVE exposure. CRWLR automates the entire firewall configuration audit — upload the file and get a prioritized findings list with vendor-specific CLI remediation in under 60 seconds.
A firewall security assessment evaluates how well your firewall enforces your intended security policy — rule hygiene, segmentation, inspection coverage, administrative hardening, and known-vulnerability exposure — then scores the overall posture. CRWLR produces a 0-100 posture score with severity-ranked findings and an attack-path map, so you see not just individual issues but how they chain into real exposure.
MSPs need multi-tenant firewall audit: per-client scoring, bulk import, scheduled rescans, and exportable audit evidence — without deploying an agent on each client device. CRWLR is agentless (upload a config, nothing to install), supports unlimited firewalls per client tenant with role-based team access, and exports auditor-ready evidence packages. Contact us for per-tenant pricing and white-label reports.
Upload a config and get a posture score, prioritized attack paths, and paste-ready CLI fixes in about 60 seconds. Agentless — nothing to install.
Start free scan2 free scans · no credit card · results in ~60s