For MSPs, consultants and assurance teams

Assessment clarity from a local export

Sentry One analyses Palo Alto PAN-OS and Fortinet FortiGate configuration exports on your own machine, applies 19 firewall-focused technical controls, then turns policy, protocol, threat-log and framework evidence into a structured client-ready report.

Assessment runs entirely offline. The optional Remediation module is the only component that contacts a device, and only when you apply an approved change plan.

Sentry One dashboard showing project trends and assessment findings
Project dashboardTrack shadow rules, vulnerabilities, compliance alignment and consolidation progress across repeat assessments.
19 technical controlsFirewall-focused checks for rule hygiene, protocol exposure, logging, change readiness and assurance context.
PAN-OS and FortiGateStructured assessment support for Palo Alto Networks and Fortinet configuration exports.
No device accessNo credentials, no firewall API access and no cloud upload for the assessment workflow.
Reviewable remediationChange plans are explicit and approved before anything is applied to a device.

Productised workflow

Explicit inputs, controls and outputs

Sentry One is easier to trust when buyers can see the operating model: exported firewall data stays local, analysis is performed against defined controls, and remediation stays reviewable.

Export inLocal analysisFramework mappingReviewable report
assessment.tsevidence.json
assessment:
  source: firewall-export.xml
  mode: offline
  credentials: false
  controls: 19
  frameworks:
    - PCI DSS
    - ISO 27001
    - NCSC CAF

report:
  brandable: true
  remediation: reviewable

Platform capabilities

Built around the assessment workflow

The product is designed for repeatable review: ingest an export, understand the evidence, explain the finding, prepare the report and plan a controlled change.

Rulebase analysis

Find rules that can never take effect

Sentry One identifies shadowed rules, redundant coverage and consolidation candidates, then explains the reasoning behind each result so assessors can defend the finding.

  • Dimension-by-dimension match reasoning.
  • Resolved source, destination, service and application context.
  • Consolidation opportunities for cleaner policy structure.
Sentry One Find rules that can never take effect screen
Rulebase analysisFind rules that can never take effect

Interactive rule evaluation

Show why one rule is affected by another

The rule map makes first-match behaviour easier to explain by showing which earlier policies shadow, overlap or duplicate the selected rule.

  • Visual relationship map for rule evaluation.
  • Clear distinction between shadowing, overlap and duplication.
  • Useful for client workshops and remediation review.
Sentry One Show why one rule is affected by another screen
Interactive rule evaluationShow why one rule is affected by another

Protocol audit

Slice the rulebase by management-plane exposure

Review SNMP, HTTPS, LDAP, DNS, NTP, syslog or any port to understand where sensitive protocols are permitted and why those rules match.

  • Per-protocol views for targeted ITHC-style checks.
  • Match reasons attached to the rules in scope.
  • Fast triage for management and infrastructure services.
Sentry One Slice the rulebase by management-plane exposure screen
Protocol auditSlice the rulebase by management-plane exposure

Remediation planning

Turn findings into a reviewable change plan

Rules are grouped, tagged and prepared for change review. Sentry One does not delete rules automatically, and approved plans stay visible before action.

  • CAB reference and change grouping support.
  • Tag and disable workflow for controlled cleanup.
  • Human approval before applying an optional change plan.
Sentry One Turn findings into a reviewable change plan screen
Remediation planningTurn findings into a reviewable change plan

Compliance readiness

Map firewall evidence to recognised frameworks

Cyber Essentials, PCI DSS v4.0, ISO/IEC 27001:2022 and NCSC CAF are presented as indicative readiness views derived from configuration evidence.

  • One configuration export, four assurance views.
  • Clear separation between technical evidence and interpretation.
  • CAF coverage identifies which firewall-evidenced outcomes are in scope.
Sentry One Map firewall evidence to recognised frameworks screen
Compliance readinessMap firewall evidence to recognised frameworks

Threat log analysis

Connect supplied log events back to policy

Where threat logs are supplied, Sentry One shows which detected events were allowed and which rules permitted them, supporting focused remediation discussions.

  • Snapshot review of supplied logs, not an ongoing monitor.
  • Allowed threat events linked back to permitting rules.
  • Better context for prioritising policy and profile changes.
Sentry One Connect supplied log events back to policy screen
Threat log analysisConnect supplied log events back to policy

Indicative readiness

One configuration export, four framework views

Sentry One relates firewall findings to Cyber Essentials, PCI DSS v4.0, ISO/IEC 27001:2022 and the NCSC Cyber Assessment Framework as indicative readiness views derived from configuration evidence.

Framework views are indicative readiness mappings based on available firewall configuration evidence. They should be reviewed alongside wider organisational evidence and professional judgement.

Consultancy delivery

Designed to sit behind your service line

The platform supports MSPs, independent security consultants and consultancies delivering repeatable firewall assurance for public-sector and regulated clients.

  • Use the dashboard to show progress across repeat assessments.
  • Use the evidence views to support workshops and remediation calls.
  • Use branded reporting so the deliverable can carry your identity.
Sentry One help and support screen
Help and supportLaunch support routes and guidance are visible inside the application.

Sentry One

Request a trial

Email [email protected] to discuss access for your MSP, consultancy or internal assurance workflow.

Email [email protected]