Use case · Enterprise & Campus · OT & ICS

Firewall policy enrichment

Rule reviews based on observed traffic, with the firewall team applying the changes.

  1. 01

    Challenge

    Firewall rules accumulate for years because nobody can prove which ones are still needed.

  2. 02

    What WireTrace sees

    Observed communication between zones and devices, and indicator matches.

  3. 03

    What WireTrace understands

    Which flows the network depends on, and which destinations are known bad.

  4. 04

    What WireTrace decides

    Rule proposals and blocklists.

  5. 05

    Integration / action

    Rule proposals exported as text in iptables, nftables, Cisco IOS or pf syntax; IP, domain and URL blocklists for firewalls to pull.

  6. 06

    Outcome

    Rule reviews based on observed traffic, with the firewall team applying the changes.

See it on your network.

A WireTrace evaluation runs on a mirror port, on your infrastructure, and shows your own devices, communications and risks.