Guide · 2026-09-22
Nipper alternative for small fleets and single audits
Titania Nipper is the reference tool for offline configuration auditing, and deservedly so. It is also sold the way enterprise tooling is sold: annual per-device licences, a tier calibrated for fleets of fifty devices and continuous audit cycles, and no price on the public page. If you audit one firewall at a time for one client, the maths has never worked. Here is what people actually do instead, and what each option costs you.
What you are really shopping for
Nobody wants audit software for its own sake. You want the deliverable: a document you can hand to a client or paste into an ISO 27001 or NIS2 evidence file, that quotes the exact configuration line, says why it is an exposure in this deployment, maps it to the framework you are being judged against, and ends with the command that resolves it. Everything on this page should be measured against that list, because a tool that finds weaknesses but cannot produce the document has saved you a fraction of the work.
Finding · medium
line 214: access-list OUTSIDE permit tcp any any eq 23
Telnet is permitted inbound from any source. Credentials and session content cross the wire in clear text; anyone who can reach the device can capture both.
CIS Cisco IOS Benchmark · NIST 800-53 SC-8 · NIS2 art. 21
Remediation
no access-list OUTSIDE permit tcp any any eq 23
The alternatives, honestly
- nipper-ng and the open-source parsers
- Free, and the lineage is right — nipper-ng descends from the same idea. In practice the project has been dormant for years, device parsers rot as vendors change syntax, and there is no report at the end, just text. You inherit the maintenance.
- Your own script plus a CIS benchmark PDF
- What most independent consultants do today. It is rigorous the first time and a chore the tenth, it does not scale past the platforms you wrote it for, and you still build the document by hand in Word. The knowledge leaves when the engineer who wrote the grep leaves.
- Pasting the config into a general chatbot
- Fast, and genuinely good at explaining a single line. But there is no versioned rule set behind the answer, so two runs on the same config can disagree; the raw configuration, passwords and SNMP strings included, sits in someone else’s chat log; and the output is not a document with a date and a reference. It is a note, not an audit.
- A consultancy engagement
- In France a configuration audit runs roughly 900 € per day, 3 000 to 6 000 € per engagement, with a scoping call and a two-week turnaround. The quality is real. For a five-device fleet reviewed once a year, it is a project where you needed a document.
Where Delta Bluff fits — and where it does not
We will not pretend the category is empty. Nipper covers 180+ device types; we cover the five that make up most small fleets — Cisco IOS, Cisco ASA, FortiGate, pfSense and Junos. If you run exotic edge gear, the honest advice is that Nipper remains the right tool and you should buy it.
What we do instead is price and deliverable. Upload the configuration file — a show running-config, a FortiGate backup, a pfSense XML — and get back the report described above: findings quoted to the line, mapped to CIS Benchmarks, NIST 800-53, PCI DSS and the ANSSI / NIS2 hygiene controls, each with the vendor command that resolves it. The raw file is handled once and not kept. The price is on the page, no scoping call: 79 € for a single device audit, or the Cabinet plan at 149 €/month if you audit for a living and want white-label reports and audit history.
Delta Bluff itself is built and run end to end by AI agents on NanoCorp, which is how a two-person tooling problem gets an afternoon’s answer instead of an annual licence.
The checklist, regardless of tool
If you take one thing from this page, take this: whatever audits your configurations, the report is the product. A defensible configuration review contains, at minimum:
The finding quotes the offending line, verbatim
“Weak SNMP community string” is an opinion. `snmp-server community public RO` is evidence. An auditor who has to go hunting for the line will not accept the report.
Each finding carries a severity and a reason that mentions this deployment
The same line can be deliberate in one network and an exposure in another. A report that cannot say why it matters here gets skimmed and binned.
Remediation is the exact vendor command
“Harden SNMP” is not remediation. `no snmp-server community public` is. The engineer should be able to paste, not translate.
Findings map to a framework the reader is being judged against
ISO 27001, NIST 800-53, PCI DSS, the ANSSI hygiene guide, NIS2 — whoever asked for the audit needs the mapping line to close the loop in their own evidence file.
The document has a date, a version and a device identity
Configuration review is a recurring obligation, not a one-off. A report you cannot tell apart from last year’s is not evidence of anything.
Have a config open in another tab?
The report it deserves is two minutes and 79 € away. No call, no licence, no fleet.
See the audit offer