Skip to Content

Webinar: Proactive Healthcare Cybersecurity for Today's Threat Landscape Register

Dark teal and black gradient

Blog

How to Parse Firewall Configs with Nipper.

Who said analyzing firewalls and network devices was something tedious and cumbersome?

Well your problems are over: Introducing Nipper, the network device configuration parser. I have found that nipper aids tremendously in helping audit and analyze network devices during our assessments, reducing tremendously the time it takes to analyze a network device configuration file. Nipper offers comprehensive and detailed reports which anyone can understand. Nipper helps security administrators to check their network devices for known vulnerabilities and configuration flaws, and attending the need for industry standards and compliance controls such as PCI, HIPAA, ISO and BITS, and the best part of using Nipper is the fact that this tool is absolutely free.

Supported Devices

  • Checkpoint VPN-1/Firewall-1
  • Cisco Catalysts
  • Cisco Content Services Switch.
  • Cisco Routers
  • Cisco Security Applicances (PIX, ASA and FWSM)
  • Juniper NetScreens Firewalls
  • Nokia IP Firewalls
  • Notel Passports
  • Sonicwall SonicOS Firewalls

How to use Nipper

  1. Download Nipper for free at : http://sourceforge.net/forum/forum.php?forum_id=722046
  2. Unzip the file to a working directory ex: c:nipper
  3. Open the command line ( start > run > cmd )
  4. Create a folder inside the working directory called config ( c:nipperconfig )
  5. Obtain a copy of your device’s config file.

Example on how to get the config of a Cisco Router.

  1. Log on to the device IOS or Console.
  2. Authenticate with your credentials.
  3. Type at the command line: show running config
  4. Copy the contents displayed.
  5. Open notepad (start -> run -> notepad)
  6. Paste the contents onto notepad and save it as

. config

Command:

Nipper.exe –

–input=c:nipperconfigfile.config –output=report_

.html

List of device type and Output:

Device
Model
SyntaxOutput
Cisco
Catalyst (IOS)
–IOS-CATALSYTHTML / XML
/ TXT
Cisco
Catalyst (NMP/CatOS)
–CATOSHTML / XML
/ TXT
Cisco
CSS
–CSSHTML / XML
/ TXT
Cisco
Security Appliance
(ASA
/ PIX / FWSM)
–PIX– ASA–FWSMHTML / XML
/ TXT
Juniper
NetScreen Firewall
–SCREENOSHTML / XML
/ TXT
Nokia
IP Firewall
–NOKIAHTML / XML
/ TXT
Nortel
Passport
–PASSPORTHTML / XML
/ TXT
SONICWALL
SonicOS Firewall
–SONICOSHTML / XML
/ TXT
Cisco
IOS
–IOS-ROUTERHTML / XML
/ TXT

Nipper Functionalities and Benefits:

  • Provides a series of recommendations to disable services that might lead to unauthorized access to the router or network.
  • Checks device OS version for vulnerabilities linking them to known vulnerability Databases.
  • Commands and recommendations to harden the network devices.
  • Help configure logging and monitoring.
  • Preform Security Audits.
  • Password complexity check.

About the Author

Tevora is a specialized management consultancy focused on cyber security, risk, and compliance services. Our combination of collaborative strategic planning and skillful execution make us a trusted partner to some of the most famous brands in the world.

Explore More In-Depth Threat Management & Response Resources

View Our Resources