Support for Palo Alto Networks Strata Cloud Manager is available now. Learn more →
Case Study
FireMon Delivers 100% Real-Time Policy Visibility Restored
A multinational missile systems and defense electronics manufacturer, serving NATO and allied defense forces worldwide.
The Results
100%
Firewall Estate Migrated to Real-Time Policy Management
50+
Firewalls Brought Under Real-Time Policy Management
3
Firewall Vendors Unified in a Single Compliance View
The Challenge
The company's firewall policy management platform was discontinued when its vendor shut down operations, leaving roughly 50 Cisco, Juniper, and Palo Alto firewalls running on an unsupported, uncertified tool. With no vendor support, the environment fell out of alignment with NIST 2 and ISO 27001 requirements, putting the organization's compliance posture and audit readiness at risk. The team had no real-time visibility into policy changes and no structured process for firewall rule recertification, so rules could go unreviewed indefinitely even as the risk of running an unsupported platform grew.
The company sought to:
- Replace an unsupported, end-of-life firewall policy platform with a fully supported, real-time alternative
- Restore real-time visibility into policy changes across a mixed Cisco, Juniper, and Palo Alto firewall estate
- Establish a structured rule recertification process mapped to NIST 2 and ISO 27001
The Solution
The company deployed FireMon Security Manager to replace the discontinued platform with a real-time policy visibility and change-detection layer spanning its entire firewall estate. FireMon Policy Planner was proven out alongside Security Manager to automate change analysis, and FireMon Policy Optimizer was added to close a rule recertification gap the evaluation surfaced, giving the team a structured, audit-ready path to continuous compliance.
- Security Manager replaced the unsupported platform with a fully supported, real-time policy visibility layer across all ~50 firewalls
- A structured rule recertification workflow now runs continuously, mapped to NIST 2 and ISO 27001 for audit-ready compliance
- An ongoing firewall rule base clean-up initiative is tracked against a risk scorecard with defined target dates
Results
- Real-time policy visibility restored across the full ~50-firewall, multi-vendor estate (Cisco, Juniper, Palo Alto)
- A structured rule recertification workflow now runs continuously, mapped to NIST 2 and ISO 27001 for audit-ready compliance
- An ongoing firewall rule base clean-up initiative is tracked against a risk scorecard with defined target dates
- A foundation is in place to extend policy management into cloud environments as the organization's infrastructure grows
"When our previous vendor shut down, we were left running security policy for close to fifty firewalls on a platform nobody was supporting anymore, with NIST 2 and ISO 27001 obligations on the line. FireMon was the only vendor willing to prove real-time detection in front of us during the POC, and once we saw how quickly Policy Optimizer closed our recertification gap, the decision made itself."
[Sr. Network Engineer] managing the selection and deployment of FireMon