Back to Guardra
Tools / Firewall review
Know what your rules allow.
Check a structured policy for broad access and rules hidden behind earlier rules. Get findings tied to your input, with clear next steps.
Need to compare rules with hospital requirements? Open the hospital assessment workspace.
Your policy stays in this tab
Rule contents are processed in your browser, never submitted to an API or saved by this tool. Reloading clears the workspace. Download a report if you want to keep it.
1. Add your rules
IPv4 · First match · v1Use Guardra JSON for one ordered rule set with a shared enforcement context. Native vendor exports must be converted to this format first. Maximum 500 rules / 1 MB.
Review coverage and limits
- Only the supplied ordered rules are reviewed, using first-match semantics within one shared enforcement context. Disabled rules are ignored.
- IPv4 addresses/CIDRs, TCP/UDP destination ports and an any-protocol wildcard are supported. No vendor configuration, IPv6, NAT, zones, objects, schedules, source ports or application identity is modelled.
- Shadowing is reported only when one earlier rule fully covers a later rule. Combined coverage and partial overlap are not detected.
- Broad-access findings describe configured scope; they do not prove exposure or a policy violation. No traffic, reachability, device vulnerability or compliance is tested. Zero findings does not mean secure.
- Priorities are review cues, not vulnerability scores. Validate changes against the original configuration, intended access and operational requirements.