# Cisco Firewall Analyzer · FMC, FTD & ASA

> Search Cisco FMC/FTD and ASA security policies, NAT, and objects, plus ACL visibility on IOS/NX-OS, and audit every configuration change, from device state, not logs.

Last updated: June 2026

Covers Cisco firewalls and ACL-bearing platforms:

- **FMC / FTD** access-control and NAT policies, objects, policy assignments, and deployable devices.
- **ASA** configuration read over SSH: interfaces, routes, objects, and access rules.
- **ACL visibility on IOS, IOS-XE, and NX-OS**: see and search access lists across routers and switches.
- **ACI fabric contracts**: tenants, EPGs, and contracts from APIC and NDO next to the perimeter firewalls.
- **Policy Analyzer on FTD**: effective access, shadowed / redundant / overly-broad rule detection, and per-rule risk scoring.
- **Change auditing** with admin attribution and volatile-field filtering.

SAMURAI analyzes configuration state, not traffic logs, and does not perform live ACL evaluation on real traffic.

## SAMURAI vs Cisco log analyzers

| | SAMURAI | Cisco log analyzers |
|---|---|---|
| Data source | Configuration state from FMC, FTD, ASA, and IOS/NX-OS devices | Syslog and traffic logs |
| Question answered | What are the rules, and who changed what, when? | What traffic passed or was denied? |
| Scope | Cisco firewalls plus routers, switches, ACI, ISE, and vCenter in one view | Usually firewall logs only |
| Deployment | Single self-hosted Docker container, air-gap friendly | Log collector or SaaS pipeline |

## Frequently asked questions

### Does SAMURAI analyze Cisco Secure Firewall (FMC/FTD)?

Yes. FMC access and NAT policies, objects, and deployable devices are first-class, and FTD configuration is read directly. You search and diff policy across every managed device from one dashboard.

### Can it read Cisco ASA?

Yes. ASA is read over SSH as part of the firewall family: interfaces, routes, objects, and access rules, alongside FMC/FTD in the same view.

### Is this a Cisco firewall log analyzer?

No, SAMURAI analyzes configuration state, not logs. It reads policies and objects from the devices themselves rather than parsing syslog, so you analyze the rules and their changes. It can forward its own events as RFC5424 syslog, but log analytics is not its focus.

### Does it do Cisco firewall rule cleanup or optimization?

For Cisco FTD, the Policy Analyzer resolves effective access, flags shadowed, redundant, and overly-broad rules, and scores each by exposure, alongside full visibility and change tracking with admin attribution. It does not do automated rule recertification or approval workflows; those lifecycle workflows are the domain of dedicated policy-management suites.

### Can I use SAMURAI as a Cisco firewall audit tool?

Yes, for configuration audit. It gives you a searchable record of FMC, FTD, and ASA policies and objects plus a change timeline with admin attribution, which is what most firewall audits actually need. It does not generate compliance-framework certification reports or flag unused rules by hit count.

### Does it support legacy Cisco PIX or ASA?

ASA is fully supported over SSH. Classic PIX is end-of-life and not a supported target; the modern equivalent, ASA and FTD, is read directly alongside FMC.

---

Canonical page: https://nometa.az/en/cisco-firewall-analyzer/
Part of SAMURAI, a self-hosted, multi-vendor network monitoring & security platform. Overview: https://nometa.az/llms.txt
Contact: info@nometa.az · Docker Hub: https://hub.docker.com/r/beyrak44/samurai
