Know what yourcloud allows
See every firewall and cloud security rule you run, understand what it permits, and fix what is wrong.
One console for the whole estate.
Every rule, every path and every finding in one place, with the evidence attached so an engineer can check the answer instead of trusting it.
Traffic Analyzer
sample10.24.6.40 → 10.24.9.15 tcp/3306
- sg-web-publicallow-https-from-internetallowed
- nsg-app-tierallow-app-to-dataallowed
- nsg-data-tierdeny-mysql-from-appblocked
Blocked at nsg-data-tier: deny-mysql-from-app is the first rule to match, at priority 210, and its action is deny. The two rule sets above it permit the flow, so removing either one would not change this answer.
Traffic Analyzer
Source, destination, protocol, port. One answer, the rule that decided it, and an honest admission when something on the path could not be evaluated.
Findings
sample- sg-bastion-ssh permits tcp/22 from 0.0.0.0/0Overly Permissive Rulecritical
- allow-app-legacy at priority 300 can never matchShadowed Rulehigh
- Three identical rules across sg-web-public and sg-web-internalDuplicate Rulemedium
Every finding carries the evidence it was derived from — the rules, the resolved addresses, and the comparison that produced it — so you can disagree with one and check.
Findings
Public exposure, overly permissive access, duplicates, unused objects, shadowed and conflicting rules. Each one confirmed before it is reported.
Rules Explorer
Every rule across every provider, shown as the addresses and ports it resolves to rather than the object names.
Impact analysis
What breaks if you remove this rule, answered by re-evaluating the flows before you approve the change.
Change history
Who changed what, when, and what the value was before, including changes made outside Cloud Patrol.
The two panels above are the real output format, filled with sample data — no customer estate is shown on this page.
Every answer carries its evidence.
A verdict you cannot check is not worth having. Cloud Patrol names the rule that decided, the device it sits on, its position in the rulebase, and the raw configuration it came from.
When something on the path cannot be evaluated, it says so. There is no confident answer built on a gap.
- DeterministicNo language model decides whether traffic is allowed.
- Four-valuedAllowed, blocked, unknown, partially evaluated. Never a guess.
- Vendor-neutralOne model. Adding a provider does not change the engine.
- Snapshot-scopedCollection never overwrites history, so you can compare.
Bring your rules. We will tell you what they permit.
A demo runs against your own configuration in read-only mode. Nothing is changed without you approving it.