How It Works

From firewall configuration to actionable security findings

ConfigSentry turns FortiGate configuration data into a structured security assessment, detailed technical findings, and clear reports for engineers and stakeholders.

Complete audit workflow

One connected process from collection to reporting

Configuration data can be uploaded manually or collected automatically. ConfigSentry then evaluates it using the selected audit template and produces reports for both technical and non-technical audiences.

Five-stage ConfigSentry workflow showing configuration input, the audit engine, assessment, reports and delivery.

1. Configuration input

Choose how configuration data reaches ConfigSentry

FortiGate configuration file ready for manual upload.

On demand

Manual configuration upload

Upload an exported FortiGate configuration and start an audit directly from your account. This is ideal for one-off reviews, testing ConfigSentry, or assessing a configuration before deployment.

Read-only collector used for scheduled configuration retrieval.

Recurring

Scheduled collection

Use a read-only ConfigSentry collector to retrieve configurations automatically and run audits at the frequency permitted by your licence.

Configuration change notification triggering a new security assessment.

Change driven

Configuration change detection

Enterprise deployments can trigger an audit after a configuration change is detected, helping teams review security impact without waiting for the next scheduled audit.

2. Audit engine

The configuration is turned into a structured model

ConfigSentry does not treat a firewall configuration as a collection of isolated text lines. It parses the configuration and builds a structured model of the FortiGate environment.

  • Firewall policies and policy order
  • Address objects and address groups
  • Services and service groups
  • Interfaces, zones and network roles
  • VDOM and global configuration
  • Administrative and security settings

3. Rule evaluation

The selected audit template controls what is checked

Each audit template contains a defined set of deterministic ConfigSentry rules. Those rules evaluate the structured configuration model and its related objects, rather than relying only on simple text matching.

Repeatable The same configuration and rule versions produce the same assessment.
Context aware Rules can follow linked objects, groups, services, interfaces and policy relationships.
Versioned Audit results retain the rule versions used when the assessment was performed.

4. Assessment

Findings explain what was checked and why it matters

01

Configuration relationships are resolved

Linked addresses, groups, services, interfaces and policy scopes are evaluated together so the finding reflects the effective configuration.

02

Checks produce structured results

Each applicable rule records its status, severity, evidence, affected configuration area and remediation guidance.

03

Relevant standards mappings are included

Where supported by the rule, findings can reference standards or guidance such as CIS, DISA STIG, ISO 27001, NIST, PCI DSS and Fortinet best practices.

5. Reports

One assessment, two views of the result

The engineer and executive reports are generated from the same audit data, keeping technical remediation and management reporting aligned.

For technical teams

Engineer report

A detailed view of every applicable check, including the evidence used to reach the result.

  • Passing, informational and failed checks
  • Finding severity and affected configuration
  • Technical explanation and remediation guidance
  • Related standards and control references
  • Configuration evidence and rule details
View the sample engineer report
For stakeholders

Executive report

A concise summary designed to communicate overall posture, significant risks and audit readiness without requiring detailed firewall knowledge.

  • Overall audit score and result summary
  • Findings grouped by severity
  • Key risks requiring attention
  • Standards and governance overview
  • Management-friendly visual summaries
View the sample executive report

6. Delivery and follow-up

Review the audit in the format that suits your team

Audit results remain available within ConfigSentry and can be downloaded for investigation, evidence gathering, remediation work or stakeholder reporting.

Report formats

Dynamic HTML PDF CSV JSON

Notifications

Users can be alerted when scheduled or change-triggered audits complete, allowing significant findings to be reviewed promptly.

Historical review

Saved audit results provide a record of the configuration, rules and findings used for that assessment.

Clear boundaries

ConfigSentry supports security review—it does not replace engineering judgement

ConfigSentry identifies configuration conditions that match its audit rules and provides evidence to support further review. Findings should still be considered alongside network design, business requirements, compensating controls and organisational risk decisions.

Standards mappings help with control discussions and evidence gathering, but an automated configuration audit cannot by itself certify that an organisation is compliant.

See it in action

Run ConfigSentry against your own FortiGate configuration

Upload a configuration to experience the complete workflow, or review the sample reports before starting your first audit.