Already live in the product
Running in production today: multi-vendor firewall support with scheduled state and log sync.
/firewallBuilt around real workflows
Highlights below describe capabilities already present in the protected app behind this page.
What teams can do here
How it works
A worked example
Say a 300-user manufacturer runs a Sophos appliance at the head office and a FortiGate at the plant, and the two-person IT team is tired of checking two vendor consoles. The Sophos connects over its API; the FortiGate forwards syslog. Every five minutes or so the refresh task re-caches rules, blocked IPs and threat signals for both devices. When an intrusion alert fires at the plant, the on-duty engineer opens the threat detail in the same workspace where the servers and tickets already live, sees the source IP was blocked, and closes the loop without a second login.
Logs, rules and blocked traffic in one review surface
Once a firewall is feeding the platform, its raw output becomes structured records instead of console screens. Traffic events land as firewall logs with source, destination, protocol and the action the appliance took, so "what did the firewall actually do at 2am?" is a filterable query, not a scroll through a vendor UI. Rules and policies are listed with their status, giving reviewers a readable inventory of what the appliance currently enforces.
Blocked traffic gets its own treatment: each blocked IP is recorded with a threat level, so the block list reads as a ranked picture of what is probing your edge rather than an undifferentiated dump. Per-device statistics aggregate the volumes over time, which is what most audits and monthly reviews really need โ the shape of the traffic, not each individual packet.
Everything sits in the same workspace as server monitoring and network monitoring, which is the point: an engineer chasing an incident moves between the firewall view, the affected server and the open ticket without switching products.
Threats named by category, not just severity
Threat records carry a named category โ malware, ransomware, phishing, botnet, trojan, worm, spyware, adware, DDoS attack or brute force โ alongside a severity and a working status. That classification matters in practice: a brute-force burst against a VPN port and an adware callout from a user laptop are both "threats", but they demand different responses, and a category-labelled queue lets you route each to the right person immediately.
On top of the threat details, typed alerts (security threat, high bandwidth, DDoS, intrusion attempt, malware, policy violation) surface the conditions worth interrupting someone for. The whitelisted-domains list closes the loop on false positives: once a legitimate destination is whitelisted it stays out of future threat noise, so the queue tends to get quieter and more trustworthy as the deployment matures.
Each threat also carries a working status โ active, mitigated, resolved or false positive โ so triage has somewhere to land instead of an undated list. Combined with per-severity filtering, a small team can honestly say which of last month's threats were acted on, which were dismissed as false positives, and which are still open.
Getting data in: API for Sophos, syslog for everyone else
Sophos appliances connect through a direct API client, which pulls state without any change to your logging pipeline. FortiGate, Palo Alto and other appliances integrate the way network gear always has โ you point their syslog output at the platform's ingestion endpoint, and the parser turns those messages into the same structured logs, blocked-IP records and threat details the Sophos path produces. The setup effort is one forwarding rule on the appliance.
A scheduled task then refreshes each firewall's cached view and aggregate statistics on roughly a five-minute cycle. The cache is a deliberate design choice: dashboards load instantly and repeated page views never hammer the appliance's management plane, while the data stays recent enough for operational review. This is a monitoring layer by design โ the appliance remains the enforcement point, and nothing here pushes rule changes to it.
Each registered device also carries its own operational record: vendor type, connection protocol, an online/offline status and a monitoring state. For a team running several appliances across sites, that turns "is the branch firewall even reporting?" into a glance at the device list โ a silent appliance stands out as offline instead of being noticed only when its logs are missed during an investigation.
Frequently asked questions
Which firewall vendors are supported?
Does this replace my firewall or push new rules to it?
How fresh is the firewall data?
What do I need to configure to get logs in?
Can I stop legitimate destinations being flagged?
What kinds of alerts does the module raise?
Can I monitor more than one firewall in the same workspace?
See also: Network monitoring ยท Network telemetry hub ยท Blog: Network monitoring tools ยท Blog: Network vulnerability assessment ยท Security & VAPT
Explore connected offerings
One workspace for every firewall you run
Sophos over API, FortiGate and Palo Alto over syslog โ rules, blocked IPs, categorised threats and typed alerts refreshed on a five-minute cycle, next to the servers and tickets they affect.
