AlgoSec for security auditing
Use Cases and Deployment Scope
We use AlgoSec to perform firewall audits ensuring there are no rule overlap and risky configurations are removed. It is also used to alert on any changes to the edge network environment and initially we were hoping the product would allow us to identify who made the changes as well, but it was unable to provide that ability.
Pros
- Traffic emulation to identify if IP traffic can flow between two points.
- Network device mapping is okay, but no better than other solutions.
- Identification of risky configurations and recommendations for remediation.
Cons
- Network mapping. Can't save any customized views unless you are an administrator.
- Rule identification. Really difficult to quickly identify rules that apply to ports and devices your are looking at.
- Can't identify who made firewall changes if AlgoSec does the change with its service account.
Return on Investment
- We never really got the solution to work properly for cloud and will be replacing it when licensing expires.
Usability
Alternatives Considered
Cisco Firepower 4100 Series


