I am in the process of re-writing the configuration for an ASA using service groups and a new naming convention. Before implementing the new ACL I would like to ensure that it matches all the rules in the current ACL. Is anyone aware of software which can take two config files and compare them to ensure that they both match up and show any differences in ports allowed and/or IP addresses allowed.
You can use compare it software which is a freeware of trial version.... which is a very good comparision tool..... it will show a different color codes if there is any difference.... else it will on the same color code....
I found some software which does the job perfectly and would highly recommend!
I performed a full rewrite on one of our complex firewalls using service object groups and a new naming convention to make the rules easier to read but I wanted the services passing through the firewall to remain the same. The following software allowed me to compare two configurations and highlight any problems.
Login to the FXOS chassis manager.
Direct your browser to https://hostname/, and log-in using the user-name and password.
Go to Help > About and check the current version:
Check the current version availa...
We have configured the outside and inside Interface with official ipv6 adresses, set a default route on outside Interface to our router, we also have definied a rule , which also gets hits, to permit tcp from inside Interface to any6.
In Syslog I also se...