ConfigSentry has moved beyond a single way to run a firewall audit. The latest work makes it easier to start with a manual check, move into recurring monitoring, and produce reports that work for both engineers and management.

The goal is simple: reduce the effort needed to understand a FortiGate configuration without hiding the technical evidence behind a vague score.

More ways to run an audit

  • Configuration upload: useful for a quick one-off review.
  • Read-only SSH retrieval: collect the configuration without manual export handling.
  • Collector-based audits: support scheduled review across managed appliances.
  • Change-triggered audits: Enterprise workflows can start an audit after a detected configuration change.

This gives teams a practical path. Start small, prove the findings are useful, and only add recurring collection when the operating need is clear.

Reports for different readers

Engineers need evidence, affected configuration sections, and remediation detail. Managers need a clearer view of severity, exposure, and progress. ConfigSentry now supports both needs through separate engineer and executive report formats.

  • Detailed findings for investigation and change planning
  • Executive summaries for risk and governance discussions
  • PDF output for sharing, retention, and review evidence

Other improvements

Recent work also includes clearer remediation guidance, stronger templates, expanded collector support, improved credential options, and more public detail about pricing, security, and data handling.

The free evaluation remains a useful starting point. It uses a focused template with fewer checks than paid audits, but it still shows the complete workflow and both report styles.

Next step: run a configsentry audit against an authorised configuration and decide whether one-off or recurring review fits your environment.