Back to Guardra

Understand your clinical network.

Connect your assets, access requirements and firewall rules. See where configured access differs from hospital intent, then assign the review and next steps.

Local assessment · No network probes · No automatic firewall changes

Work stays in this tab. Download an assessment file to save assets, rules and review actions; reload it to continue later. There is no automatic storage or team synchronization. Use infrastructure metadata only; patient records are not needed.

Sign in to a persistent team workspace

Untitled hospital assessment

No unsaved changes · 0/100 assets · 0/20 zones · 0/100 requirements

Hospital zones (0)

No hospital zones yet. Add the first zone below.

Add zone

Asset inventory (0)

No asset inventory yet. Add the first asset below.

Add asset

Up to 10,000 asset/service checks · Saved inputs only

Assessment scope and limitations
  • Configuration checks only. No packets are sent and connectivity is not verified. A matching rule is not proof that a path is reachable.
  • Each requirement checks all inventoried source/destination asset pairs in the named zones for one TCP/UDP destination port. Other addresses, ports, protocols and paths without requirements are not assessed.
  • Hospital zones group assets for requirements; they are not firewall interface or vendor security zones. All input rules must already share a single enforcement context.
  • No matching explicit rule is unknown; the tool does not assume an implicit deny. Empty zones and missing inputs are coverage gaps.
  • Requirements and approvals are entered by the user, not authenticated sign-offs. Review statuses record decisions; they do not change findings or verify remediation.
  • Confirm clinical dependencies and obtain clinical/network approval before implementing changes. This tool never changes a firewall.
  • Only the supplied ordered rules are reviewed, using first-match semantics within one shared enforcement context. Disabled rules are ignored.
  • IPv4 addresses/CIDRs, TCP/UDP destination ports and an any-protocol wildcard are supported. No vendor configuration, IPv6, NAT, zones, objects, schedules, source ports or application identity is modelled.
  • Shadowing is reported only when one earlier rule fully covers a later rule. Combined coverage and partial overlap are not detected.
  • Broad-access findings describe configured scope; they do not prove exposure or a policy violation. No traffic, reachability, device vulnerability or compliance is tested. Zero findings does not mean secure.
  • Priorities are review cues, not vulnerability scores. Validate changes against the original configuration, intended access and operational requirements.