Firewall exposure management

Audit every firewall.
Prove every fix.

CRWLR finds exploitable paths hidden in FortiGate, Palo Alto, Sophos, Check Point, and Cisco ASA configurations — then gives your team prioritized CLI fixes and audit-ready evidence.

2 free scans · no credit card · results in ~60s · see pricing

175 security checks5 firewall vendors0 raw configs stored
SAMPLE AUDIT — FortiGate 100F · 287 policiesComplete
34
Posture score
At risk
Critical
3
2 attack paths
High
8
5 exposed policies
CRITICALFW-C-001CIS 2.2 · PCI 1.3
WAN → LAN policy allows unrestricted access

Policy 42 creates a direct path from the internet to the internal network without inspection.

INTERNETPOLICY 42INTERNAL LAN
Recommended remediation
set ips-sensor "default"

Explore the full interactive demo →

Built for the firewalls your network already runs

One clear view of exposure

From configuration file
to defensible action.

Built for security leaders who need evidence and network engineers who need exact remediation — from the same scan.

01

See exploitable paths

Connect isolated configuration issues into the routes an attacker could actually use — WAN exposure, missing inspection, and segmentation gaps chained into one map.

02

Fix with confidence

Every finding ships with vendor-specific CLI remediation and the context behind the change, ready to paste into FortiGate, PAN-OS, SFOS, Check Point, or ASA.

03

Prove improvement

Turn every scan into measurable posture history, acknowledged-risk tracking, and audit-ready evidence mapped to the controls your auditors check.

Compliance

Mapped to CIS Benchmarks, PCI DSS, and NIST 800-41

Every finding cites the controls your auditors check. CRWLR maps results to the CIS Benchmarks for your vendor, PCI DSS Requirement 1, and NIST 800-41 firewall policy guidelines — so a scan doubles as audit-ready evidence for your next rule review.

CIS BenchmarksPCI DSS Requirement 1NIST 800-41

Built for sensitive infrastructure

Your configuration is analyzed.
Your raw file is not retained.

Configs are parsed in memory and never written to disk or database — only the normalized findings are stored. Optional client-side sanitizer strips secrets before anything leaves your machine.

In-memoryconfig processingTenant-isolatedresults and accessEU-hostedinfrastructure (Frankfurt)Read the security architecture →

For security teams

One posture score per firewall, evidence behind every number

Attack-path maps, firmware CVE correlation, and per-policy grading — with paste-ready CLI remediation your network team can act on the same day.

Run the sample audit →

For MSPs

Every client firewall in one fleet dashboard

Per-client scoring, bulk import, scheduled re-scans, role-based team access, and exportable evidence packages for client compliance reporting.

See MSP pricing →

Frequently asked questions

What is a firewall configuration audit?

A firewall configuration audit is a systematic review of your firewall rules, policies, and system settings to find security gaps, misconfigurations, and compliance violations. CRWLR automates this process — upload your config file and get a security posture score with prioritized findings in under 60 seconds.

Which firewall vendors does CRWLR support?

CRWLR supports Fortinet FortiGate (.conf), Palo Alto Networks (XML), Sophos XG/XGS (XML or PostgreSQL dump), Check Point R80+ (JSON from mgmt_cli), and Cisco ASA (show running-config). Each vendor gets tailored remediation commands you can paste directly into your firewall CLI.

How does attack path analysis work?

Attack path analysis maps how multiple individual misconfigurations can chain together into an exploitable route through your network. For example, an overly permissive WAN rule combined with missing SSL inspection and no IPS profile creates a path for data exfiltration that no single finding would reveal on its own.

Is my firewall configuration stored?

No. Your raw config file is parsed entirely in memory and never written to disk or database. This is an architecture-level guarantee, not just a policy. Only the normalized analysis results (findings, scores, remediation) are stored — never the original configuration.

How often should firewall rules be reviewed?

PCI DSS v4.0 Req 1.2.7 requires firewall rule reviews every 6 months. Many frameworks and cyber-insurers also expect more frequent reviews. For organizations with frequent changes, monthly automated scans catch configuration drift before it becomes a compliance gap or security risk.

What compliance frameworks does CRWLR map to?

CRWLR maps findings to CIS Benchmarks (FortiGate, Palo Alto, Sophos), PCI DSS Requirement 1 (network security controls), and NIST 800-41 (firewall policy guidelines). Each finding shows which compliance controls it affects.

Can MSPs use CRWLR for multiple clients?

Yes. CRWLR supports multi-tenant fleet management — manage all your client firewalls from one dashboard with per-client scoring, bulk import via ZIP, and exportable audit evidence packages for compliance reporting.

How does CVE cross-referencing work?

CRWLR detects your exact firmware version and cross-references it against CISA Known Exploited Vulnerabilities (KEV), NVD, and vendor-specific PSIRT feeds. It only alerts on CVEs for features actually enabled on your firewall — no noise from vulnerabilities in disabled modules.

How do you audit a firewall configuration?

Export your firewall configuration (FortiGate .conf, Palo Alto or Sophos XML, Check Point JSON or Gaia clish, or Cisco ASA show running-config) and analyze it for overly permissive rules, missing security profiles, exposed management interfaces, weak VPN crypto, zone-segmentation gaps, and firmware CVE exposure. CRWLR automates the entire firewall configuration audit — upload the file and get a prioritized findings list with vendor-specific CLI remediation in under 60 seconds.

What is a firewall security assessment?

A firewall security assessment evaluates how well your firewall enforces your intended security policy — rule hygiene, segmentation, inspection coverage, administrative hardening, and known-vulnerability exposure — then scores the overall posture. CRWLR produces a 0-100 posture score with severity-ranked findings and an attack-path map, so you see not just individual issues but how they chain into real exposure.

What is the best firewall audit tool for MSPs?

MSPs need multi-tenant firewall audit: per-client scoring, bulk import, scheduled rescans, and exportable audit evidence — without deploying an agent on each client device. CRWLR is agentless (upload a config, nothing to install), supports unlimited firewalls per client tenant with role-based team access, and exports auditor-ready evidence packages. Contact us for per-tenant pricing and white-label reports.

See what your firewall is actually allowing

Upload a config and get a posture score, prioritized attack paths, and paste-ready CLI fixes in about 60 seconds. Agentless — nothing to install.

Start free scan

2 free scans · no credit card · results in ~60s