FortiGate Policy Audit

v0.2 — everything runs in your browser

Audit your FortiGate policies.
Your config never leaves this page.

Drop in a FortiOS 7.x config and get an instant policy audit — shadowed rules, any-any exposure, and CIS hardening gaps. All analysis runs locally in your browser: nothing is uploaded, no account, no install.

✓ Config analysis 100% local — zero uploads ✓ Works offline & air-gapped ✓ Single HTML file — save & keep it

Shadowed rules

Finds policies that can never match — including a broad accept silently hiding a deny below it. Resolves address groups, subnets, and interface any.

Any-any exposure

Flags overly permissive policies where source, destination, or service is all, ranked by severity.

CIS hardening

System-level checks against the CIS FortiOS Benchmark: admin timeout, HTTP mgmt, default admin, password policy, NTP, syslog, SNMP, USB auto-install.

Static configuration analysis only. It does not check license or certificate expiry, firmware CVEs, VPN tunnel status, or threat intelligence — a clean result is not a guarantee the firewall is secure. The full report lists exactly what is and isn't covered.

Drop your FortiGate config here

or click to browse

.conf · .txt · .log — FortiOS 7.x · use "show full-configuration" output for complete results

 · 
Tip: save this page (⌘S / Ctrl+S) and run it on an offline machine.

No analysis yet.

Load a FortiGate config in the Analyze tab — the summary appears here.

No results yet.

Run an analysis first — the full policy table and findings appear here.

What this tool does

FortiGate Policy Audit is a single-file, client-side audit tool for FortiOS 7.x configurations. It finds:

  • Shadowed rules — policies that can never match because an earlier, broader rule always wins (including a broad accept silently hiding a deny).
  • Any-any exposure — overly permissive policies where source, destination, or service is all, ranked by severity.
  • CIS hardening gaps — system-level checks against the CIS FortiOS Benchmark: management access, admin accounts, password & lockout policy, SNMP, logging, weak IPsec crypto, cleartext secrets.

Privacy

All analysis runs locally in your browser. Your config is never uploaded, and the analysis path makes zero network requests — don't take our word for it: open DevTools → Network and watch it stay empty while you analyze. Save this page (⌘S / Ctrl+S) and it works offline and air-gapped. The only network actions are ones you explicitly trigger — the feedback form and the updates signup — and neither ever includes your config.

Scope & limitations

Static configuration analysis only, validated for FortiOS 7.x single-VDOM configs. It does not check license or certificate expiry, firmware CVEs, VPN tunnel status, routing correctness, rule hit counts, NAT/VIP correctness, IPv6 policies, or threat intelligence. A clean report is not a guarantee the firewall is secure. Findings require human review before client delivery.

Hardening findings cite the CIS FortiOS Benchmark ↗.

Feedback

Found a false positive, or missing a check you need? Send feedback — it goes straight to the person building this.

Updates

Get notified when new checks land — no tracking, no spam, unsubscribe any time.

Feedback

Only what you type below is sent — never your config. Your firewall analysis stays 100% in this browser.