Review firewall security policy on PAN-OS, FortiOS, and ASA for shadow rules, any-any, and missing log-end. Use when a rule is changing or a quarterly hygiene pass is due.