Firevyzer Firewall ACL
change analysis
Docs Sign in

Every flow a firewall change touches — in a handful of traffic classes.

Instead of tracing one packet at a time, Firevyzer partitions the entire packet space into symbolic traffic classes — concise sets that together cover every possible flow. Diff two policies and see exactly which classes change verdict, and the rule responsible for each.

Sign in to Firevyzer

Authentication handled by Amazon Cognito — passwords, MFA, and resets never touch this app.

Change report edge-acl · v41 → v42
Newly allowed 10.2.0.0/2410.0.4.10 : 443 now by rule 12 · allow — was default-deny
Newly denied any10.0.4.10 : any except 22 now by rule 7 · drop — was rule 9 · allow
2 traffic classes changed select a rule to trace
Every possible flow, covered

Symbolic traffic classes

Each class is one concise set standing in for countless flows — including over-broad shapes like any port except 22 that flow-by-flow checks slip right past.

Complete by construction

The classes partition the entire packet space, so coverage is total — no sampling, no flow you forgot to test. Every packet lands in exactly one class.

Diff by class, with provenance

Diff two policies and get the exact classes whose verdict flips — each tagged with the rule that decides it now, and the one that decided it before.