What problem does it solve? Firewall rulebases accumulate any-any permits, shadowed rules, missing logging, weak VPN crypto, and exposed management services that are hard to spot by manual review. This Skill audits normalized Cisco, Fortinet, Palo Alto, and Juniper configurations against a vendor-neutral check catalog and produces prioritized, evidence-grounded findings instead of vague verdicts. ## Core Features & Use Cases - Vendor-neutral rulebase audit: Runs security checks (any-any, shadowed/redundant/overlapping rules, missing deny-all, exposed management, weak IKE/IPsec crypto) and operational checks (unused objects, oversized groups, naming gaps) over the shared parsing-* intermediate JSON schema. - Device-plane hardening coverage: Evaluates SSH root login, password/lockout policy, zone screens, host-inbound exposure, control-plane protection, IPv6 posture, and remote logging completeness. - Severity and confidence discipline: Every finding carries a severity, a definitive/heuristic confidence label, affected references, rationale, and per-vendor remediation snippets; skipped checks are reported rather than silently dropped. - Use Case: Given a raw Juniper SRX configuration, the Skill routes it through the matching parser, then reports that the policy set is empty, root SSH login is allowed, and the configured IDP/UTM stack is attached to no policy — each with concrete Junos fix commands. ## Quick Start Use the firewall-best-practices-audit skill to audit this parsed firewall configuration and list the prioritized findings with remediation.