Remotely determining unused firewall rules
Hi Folks,
I'm trying figure out a way to programatically find unused firewall rules on my firewalls. Each fortigate has a nifty feature that tells us when a rule isn't being hit. But we have a few dozen firewalls and logging into each one isn't appealing.
We have both a fortimanager and fortianalyzer so we could use that as well. But so far I haven't found this information being stored on either device.
I could potentially use the api and connect to each firewall but I am not sure where I would even find this command to query assuming it is even there. Anyone know of a way to do this?
