Multi-Vendor

Multi-Vendor Firewall Change Management

33 vendors across on-prem, cloud, SASE, open source, and virtualization. Manage all your firewalls from a single platform with vendor-agnostic rule normalization.

Enterprise On-Prem

PA
Production Ready

Palo Alto Networks

PAN-OS XML API

Authentication:API Key
Tested Versions:PA-VM 10.x, 11.x
FT
Production Ready

Fortinet FortiGate

FortiOS REST API

Authentication:API Token
Tested Versions:FortiOS 6.x, 7.x
CP
Production Ready

Check Point

R80+ Web API

Authentication:API Key + Session
Tested Versions:R80.40, R81.x
CS
Production Ready

Cisco ASA

REST API

Authentication:Basic Auth
Tested Versions:ASA 9.x
FD
Supported

Cisco FTD / FMC

FMC REST API

Authentication:Token Auth
Tested Versions:FMC 7.x
MX
Supported

Cisco Meraki MX

Dashboard REST v1

Authentication:API Key
Tested Versions:MX series
JN
Supported

Juniper SRX

Junos REST + NETCONF

Authentication:API Token / Certificate
Tested Versions:Junos 21.x, 22.x
F5
Supported

F5 BIG-IP AFM

iControl REST

Authentication:Basic / Token Auth
Tested Versions:BIG-IP 15.x, 16.x
SO
Supported

Sophos XGS

Sophos Central REST

Authentication:API Token
Tested Versions:SFOS 19.x, 20.x
SW
Supported

SonicWall

SonicOS REST API

Authentication:API Token
Tested Versions:SonicOS 7.x
WG
Supported

WatchGuard Firebox

REST API

Authentication:Token Auth
Tested Versions:Fireware 12.x
BC
Supported

Barracuda CloudGen

REST (JSON-RPC)

Authentication:API Token
Tested Versions:CloudGen 8.x, 9.x
FP
Supported

Forcepoint NGFW

SMC REST API

Authentication:API Key
Tested Versions:SMC 6.x
HW
Supported

Huawei USG

REST / NETCONF

Authentication:Token Auth
Tested Versions:USG6000 V500
HS
Supported

Hillstone

REST API

Authentication:API Token
Tested Versions:StoneOS 5.x
SS
Supported

Stormshield SNS

REST API

Authentication:Token Auth
Tested Versions:SNS 4.x
AC
Supported

Cisco ACI / APIC

APIC REST API

Authentication:Token Auth
Tested Versions:ACI 5.x, 6.x

Cloud

AW
Production Ready

AWS

AWS SDK (EC2)

Authentication:IAM Credentials
Tested Versions:EC2, VPC
AZ
Production Ready

Microsoft Azure

Azure SDK

Authentication:Service Principal
Tested Versions:NSG, Azure Firewall
GC
Supported

Google Cloud Platform

@google-cloud/compute

Authentication:Service Account
Tested Versions:VPC, Cloud Armor
OC
Supported

Oracle Cloud

OCI REST API

Authentication:API Key
Tested Versions:OCI VCN
DO
Supported

DigitalOcean

REST v2

Authentication:API Token
Tested Versions:DO Firewalls
AL
Supported

Alibaba Cloud

OpenAPI

Authentication:AccessKey
Tested Versions:ECS Security Groups

SASE / FWaaS

ZS
Supported

Zscaler ZIA

ZIA REST API

Authentication:Obfuscated API Key
Tested Versions:ZIA
CT
Supported

Cato Networks

GraphQL API

Authentication:API Key
Tested Versions:Cato SASE Cloud
CF
Supported

Cloudflare Magic Firewall

REST v4

Authentication:API Token
Tested Versions:Cloudflare Enterprise
NS
Supported

Netskope

REST API

Authentication:API Token
Tested Versions:Netskope Security Cloud

Open Source

OP
Production Ready

OPNsense

REST API

Authentication:API Key + Secret
Tested Versions:22.x, 23.x, 24.x
PF
Compatible

pfSense

OPNsense Compatible

Authentication:Via OPNsense driver
Tested Versions:2.6.x, 2.7.x
VY
Supported

VyOS

HTTP API

Authentication:API Key
Tested Versions:VyOS 1.4+
MT
Supported

MikroTik RouterOS

REST API (v7.1+)

Authentication:Basic Auth
Tested Versions:RouterOS 7.x

Virtualization

NX
Supported

VMware NSX

NSX-T Policy REST

Authentication:Basic / SAML Auth
Tested Versions:NSX-T 3.x, 4.x
NF
Supported

Nutanix Flow

Prism Central REST

Authentication:Basic Auth
Tested Versions:Prism Central 2023.x

Vendor Integration Details

Palo Alto Networks - PAN-OS XML API

Authentication

API Key

Supported Operations

  • Rule CRUD
  • Policy queries
  • Health monitoring
  • Config backup

Tested Versions

PA-VM 10.x, 11.x

Deployment Models

Physical, VM, Cloud (AWS, Azure, GCP)

Fortinet FortiGate - FortiOS REST API

Authentication

API Token

Supported Operations

  • Firewall policies
  • Address objects
  • Services
  • VPN config

Tested Versions

FortiOS 6.x, 7.x

Deployment Models

FortiGate appliances, VM, Cloud

Check Point - R80+ Web API

Authentication

API Key + Session

Supported Operations

  • Access rules
  • NAT rules
  • Object management
  • Policy install

Tested Versions

R80.40, R81.x

Deployment Models

Check Point appliances, CloudGuard

Cisco ASA - REST API

Authentication

Basic Auth

Supported Operations

  • Access lists
  • Object groups
  • NAT rules
  • VPN

Tested Versions

ASA 9.x

Deployment Models

ASA 5500-X, Firepower, ASAv

Cisco FTD / FMC - FMC REST API

Authentication

Token Auth

Supported Operations

  • Access policies
  • Object management
  • Deploy tasks
  • Health

Tested Versions

FMC 7.x

Deployment Models

Firepower appliances, FTDv

Cisco Meraki MX - Dashboard REST v1

Authentication

API Key

Supported Operations

  • L3 firewall rules
  • L7 rules
  • VPN config
  • Content filtering

Tested Versions

MX series

Deployment Models

Meraki MX appliances

Juniper SRX - Junos REST + NETCONF

Authentication

API Token / Certificate

Supported Operations

  • Security policies
  • NAT
  • Zones
  • Candidate config commit

Tested Versions

Junos 21.x, 22.x

Deployment Models

SRX Series, vSRX

F5 BIG-IP AFM - iControl REST

Authentication

Basic / Token Auth

Supported Operations

  • AFM firewall rules
  • Address lists
  • Port lists
  • Policies

Tested Versions

BIG-IP 15.x, 16.x

Deployment Models

BIG-IP appliances, VE

Sophos XGS - Sophos Central REST

Authentication

API Token

Supported Operations

  • Firewall rules
  • NAT
  • Web filtering
  • IPS

Tested Versions

SFOS 19.x, 20.x

Deployment Models

XGS Series, XG VM

SonicWall - SonicOS REST API

Authentication

API Token

Supported Operations

  • Access rules
  • NAT policies
  • Objects
  • Zones

Tested Versions

SonicOS 7.x

Deployment Models

TZ, NSa, NSsp Series

WatchGuard Firebox - REST API

Authentication

Token Auth

Supported Operations

  • Firewall policies
  • Aliases
  • NAT
  • VPN

Tested Versions

Fireware 12.x

Deployment Models

Firebox appliances, FireboxV

Barracuda CloudGen - REST (JSON-RPC)

Authentication

API Token

Supported Operations

  • Firewall rules
  • NAT
  • VPN
  • URL filtering

Tested Versions

CloudGen 8.x, 9.x

Deployment Models

Barracuda appliances, Cloud

Forcepoint NGFW - SMC REST API

Authentication

API Key

Supported Operations

  • Access rules
  • NAT
  • VPN
  • Deep inspection

Tested Versions

SMC 6.x

Deployment Models

Forcepoint NGFW appliances

Huawei USG - REST / NETCONF

Authentication

Token Auth

Supported Operations

  • Security policies
  • NAT
  • Zones
  • VPN

Tested Versions

USG6000 V500

Deployment Models

USG Series appliances

Hillstone - REST API

Authentication

API Token

Supported Operations

  • Security policies
  • NAT
  • VPN
  • Objects

Tested Versions

StoneOS 5.x

Deployment Models

Hillstone A/E/X Series

Stormshield SNS - REST API

Authentication

Token Auth

Supported Operations

  • Filter rules
  • NAT
  • Objects
  • VPN

Tested Versions

SNS 4.x

Deployment Models

SNS appliances, EVA

Cisco ACI / APIC - APIC REST API

Authentication

Token Auth

Supported Operations

  • Contracts
  • Filters
  • EPGs
  • Tenant policies

Tested Versions

ACI 5.x, 6.x

Deployment Models

Nexus 9000 + APIC

AWS - AWS SDK (EC2)

Authentication

IAM Credentials

Supported Operations

  • Security Groups
  • Network ACLs
  • VPC rules
  • WAF

Tested Versions

EC2, VPC

Deployment Models

AWS Cloud

Microsoft Azure - Azure SDK

Authentication

Service Principal

Supported Operations

  • NSG rules
  • Azure Firewall
  • Application Gateway
  • WAF

Tested Versions

NSG, Azure Firewall

Deployment Models

Azure Cloud

Google Cloud Platform - @google-cloud/compute

Authentication

Service Account

Supported Operations

  • VPC firewall rules
  • Hierarchical policies
  • Cloud Armor

Tested Versions

VPC, Cloud Armor

Deployment Models

GCP Cloud

Oracle Cloud - OCI REST API

Authentication

API Key

Supported Operations

  • Security lists
  • NSGs
  • Network firewall rules

Tested Versions

OCI VCN

Deployment Models

Oracle Cloud

DigitalOcean - REST v2

Authentication

API Token

Supported Operations

  • Cloud firewall rules
  • Droplet assignment

Tested Versions

DO Firewalls

Deployment Models

DigitalOcean Cloud

Alibaba Cloud - OpenAPI

Authentication

AccessKey

Supported Operations

  • Security group rules
  • Cloud firewall policies

Tested Versions

ECS Security Groups

Deployment Models

Alibaba Cloud

Zscaler ZIA - ZIA REST API

Authentication

Obfuscated API Key

Supported Operations

  • Firewall rules
  • URL filtering
  • DLP
  • Cloud app control

Tested Versions

ZIA

Deployment Models

Zscaler Cloud

Cato Networks - GraphQL API

Authentication

API Key

Supported Operations

  • WAN firewall rules
  • Internet firewall
  • Network rules

Tested Versions

Cato SASE Cloud

Deployment Models

Cato Cloud

Cloudflare Magic Firewall - REST v4

Authentication

API Token

Supported Operations

  • Magic Firewall rules
  • WAF rules
  • Rate limiting

Tested Versions

Cloudflare Enterprise

Deployment Models

Cloudflare Edge

Netskope - REST API

Authentication

API Token

Supported Operations

  • Firewall policies
  • Steering
  • Real-time policies

Tested Versions

Netskope Security Cloud

Deployment Models

Netskope Cloud

OPNsense - REST API

Authentication

API Key + Secret

Supported Operations

  • Firewall rules
  • Aliases
  • NAT
  • Traffic shaping

Tested Versions

22.x, 23.x, 24.x

Deployment Models

Bare metal, VM, Cloud instances

pfSense - OPNsense Compatible

Authentication

Via OPNsense driver

Supported Operations

  • Rules
  • Aliases
  • NAT

Tested Versions

2.6.x, 2.7.x

Deployment Models

Netgate appliances, pfSense VM

VyOS - HTTP API

Authentication

API Key

Supported Operations

  • Firewall rules
  • NAT
  • Zones
  • Routing policies

Tested Versions

VyOS 1.4+

Deployment Models

Bare metal, VM, Cloud

MikroTik RouterOS - REST API (v7.1+)

Authentication

Basic Auth

Supported Operations

  • Firewall filter
  • NAT
  • Mangle
  • Address lists

Tested Versions

RouterOS 7.x

Deployment Models

MikroTik routers, CHR

VMware NSX - NSX-T Policy REST

Authentication

Basic / SAML Auth

Supported Operations

  • DFW rules
  • Gateway firewall
  • Security groups
  • Policies

Tested Versions

NSX-T 3.x, 4.x

Deployment Models

VMware vSphere / vCloud

Nutanix Flow - Prism Central REST

Authentication

Basic Auth

Supported Operations

  • Security policies
  • Microsegmentation
  • App-centric rules

Tested Versions

Prism Central 2023.x

Deployment Models

Nutanix AHV

How It Works

Vendor-Agnostic Normalization

FwChange translates vendor-specific configurations into a unified rule format, allowing you to work with all your firewalls using consistent terminology.

1

Driver Architecture

Each vendor has a dedicated driver implementing a common interface. Add new vendors by implementing the same interface.

2

Rule Normalization

Vendor-specific rules are converted to a normalized format for analysis, optimization, and approval workflows.

3

Push to Device

Approved changes are translated back to vendor-specific syntax and pushed via the appropriate API.

Frequently Asked Questions

How do you store firewall credentials?

All credentials are encrypted at rest using AES-256-GCM. Credentials are only decrypted in memory during API calls and never logged or exposed.

Can I manage mixed vendor environments?

Yes. FwChange is designed for heterogeneous firewall fleets. Manage Palo Alto at the perimeter, Fortinet at branches, and Check Point in the datacenter—all from one platform.

What if my vendor isn't supported?

We can develop custom drivers for enterprise customers. Contact us with your vendor and API documentation, and we'll provide an integration timeline.

Which versions are supported?

We support the last 2-3 major releases of each vendor. Check the detailed integration table above for specific version numbers tested with your firewall.

Ready to Unify Your Firewall Management?

See how FwChange simplifies multi-vendor firewall operations.

Try Free Scanner