Need to audit a PIX configuration

I am in the situation where I need to audit a network that is being protected by a PIX 515 firewall (v4.4). Besides (1) just getting a configuration report with "write t" and giving myself a headache trying to decipher it, and (2) running nessus against the box to see the practical exposures (and yes, I have permission to do so), does anyone have any ideas, guides, tools, white papers, references, etc. whereby I can do a reasonable audit/assessment of the firewall's configuration?

Thanks,
Wayne
eisenbergwAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

lrmooreCommented:
You mean people are still running 4.x on PIX? Yipes!

There are tools for IOS configs, but none that I'm aware of for PIX.

http://www.cisecurity.org/bench_cisco.html

If your nessus or other tools can't penetrate from outside, then it's doing it's job.
Else, you need to have a PIX person look it over for you and provide input. Nothing beats "eyes on" from an expert.
You can post here if you want and we can comment, just mask the real ip addresses/names/passwords
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
lrmooreCommented:
You can read all the security advisories for the PIX and compare..
http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/prod_security_advisories_list.html
0
GnartCommented:
Cisco has browser based Pix Device Manager (PDM) free but it is included only with 6.x.  You can check.  Cisco's Policy Secure Manager (CPSM) and Cisco Work, buth they cost $....

PDM http://www.cisco.com/en/US/products/sw/netmgtsw/ps2032/index.html

cheers
0
eisenbergwAuthor Commented:
OK, thanks. I wasn't sure that there was anything available at all. The cisecurity stuff looks good for the other things, though.

0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Software Firewalls

From novice to tech pro — start learning today.