I’m Chris Hansford, the founder of Secdit and the person building ConfigSentry. I’ve worked as a network and firewall engineer for more than 20 years, across permanent, consulting, and contracting roles.

Over that time I’ve worked with organisations of different sizes, across many vendors and technologies, and carried out thousands of firewall configuration audits and reviews.

I created ConfigSentry because I kept running into the same firewall-audit problems. Reviews took a lot of manual effort, important findings were easy to miss, and the final result was often difficult to explain to anyone outside the engineering team.

The problems kept repeating

The environments changed, but many of the review problems were familiar:

  • Firewall rules that had become much broader than the original request
  • Weak or incomplete logging
  • Management access exposed on the wrong interfaces
  • Old objects and exceptions that no longer had a clear owner
  • Temporary changes that quietly became permanent
  • Reports that either lacked technical evidence or were too detailed for management

Manual review is still important, but repeating the same checks by hand is slow and inconsistent. I wanted a better way to handle the repeatable work without pretending that software can replace engineering judgement.

Why ConfigSentry focuses on FortiGate

I decided to focus deeply on FortiGate rather than trying to support every firewall vendor at a shallow level. FortiGate configurations are detailed, and many risks only become clear when version information, VDOM context, policies, objects, interfaces, profiles, and global settings are reviewed together.

That focus gives ConfigSentry room to produce more specific findings and more useful remediation guidance.

What I want ConfigSentry to achieve

  • Make reviews repeatable: apply the same checks consistently every time.
  • Show the evidence: identify the relevant configuration, not just a generic warning.
  • Help engineers act: provide practical remediation guidance.
  • Make results easier to share: produce detailed engineer reports and clearer executive summaries.
  • Catch drift: make it easier to rerun checks after changes and confirm that remediation stayed in place.

ConfigSentry is still growing, and I’m building it openly and honestly. I would rather be clear about what the product can and cannot do than hide behind broad claims.

If you manage FortiGate firewalls, you can run a free ConfigSentry audit against an authorised configuration and see whether the approach is useful in your own environment.