Audit your FortiGate policies.
Your config never leaves this page.
Drop in a FortiOS 7.x config and get an instant policy audit — shadowed rules, any-any exposure, and CIS hardening gaps. All analysis runs locally in your browser: nothing is uploaded, no account, no install.
Shadowed rules
Finds policies that can never match — including a broad accept silently hiding a deny below it. Resolves address groups, subnets, and interface any.
Any-any exposure
Flags overly permissive policies where source, destination, or service is all, ranked by severity.
CIS hardening
System-level checks against the CIS FortiOS Benchmark: admin timeout, HTTP mgmt, default admin, password policy, NTP, syslog, SNMP, USB auto-install.
Static configuration analysis only. It does not check license or certificate expiry, firmware CVEs, VPN tunnel status, or threat intelligence — a clean result is not a guarantee the firewall is secure. The full report lists exactly what is and isn't covered.
Drop your FortiGate config here
or click to browse
.conf · .txt · .log — FortiOS 7.x · use "show full-configuration" output for complete results
No analysis yet.
Load a FortiGate config in the Analyze tab — the summary appears here.
No results yet.
Run an analysis first — the full policy table and findings appear here.
What this tool does
FortiGate Policy Audit is a single-file, client-side audit tool for FortiOS 7.x configurations. It finds:
- Shadowed rules — policies that can never match because an earlier, broader rule always wins (including a broad accept silently hiding a deny).
- Any-any exposure — overly permissive policies where source, destination, or service is
all, ranked by severity. - CIS hardening gaps — system-level checks against the CIS FortiOS Benchmark: management access, admin accounts, password & lockout policy, SNMP, logging, weak IPsec crypto, cleartext secrets.
Privacy
All analysis runs locally in your browser. Your config is never uploaded, and the analysis path makes zero network requests — don't take our word for it: open DevTools → Network and watch it stay empty while you analyze. Save this page (⌘S / Ctrl+S) and it works offline and air-gapped. The only network actions are ones you explicitly trigger — the feedback form and the updates signup — and neither ever includes your config.
Scope & limitations
Static configuration analysis only, validated for FortiOS 7.x single-VDOM configs. It does not check license or certificate expiry, firmware CVEs, VPN tunnel status, routing correctness, rule hit counts, NAT/VIP correctness, IPv6 policies, or threat intelligence. A clean report is not a guarantee the firewall is secure. Findings require human review before client delivery.
Hardening findings cite the CIS FortiOS Benchmark ↗.
Feedback
Found a false positive, or missing a check you need? Send feedback — it goes straight to the person building this.
Updates
Get notified when new checks land — no tracking, no spam, unsubscribe any time.