> Source: https://docs.nometa.az/v4.8.0/features/policy-analyzer

# Policy Analyzer

SAMURAI's multi-vendor [firewall analyzer](https://docs.nometa.az/md/v4.8.0/firewall-analyzer.md), covering Palo Alto, Cisco FMC, Cisco FTD, FortiGate, Cisco ACI and Cisco ISE. It scores per-rule risk against operator-rated zone trust and criticality, detects anomalies (shadowed, redundant and overly permissive rules, split into actionable and advisory), derives cleanup and optimization recommendations with vendor-native config candidates, and browses the actual rule base with server-side filtering and export.

Zone-pair **segregation** is checked against an interactive baseline matrix (which zone may talk to which), and **compliance packs** written as YAML policy-as-code produce per-framework reports. A graph view visualizes EPGs, zones, contracts and rules as a clickable policy map. Access requires the policy-analysis permission.
