Reviewing firewall rules

Recently, the guys at matasano have released Flint, a firewall rules checker. It's GPL and runs on sinatra.

alt text
(source: runplaybook.com)

Looks very promising. Although I haven't tried it yet. There's only support for PIX/ASA firewalls, but they will be adding others in the future.

EDIT:

I have installed it and tested it. Installation is very simple. As for the analysis, I fed it with a complex firewall configuration and it took a long time to analyze. Results were mostly correct, but there were parsing errors.

Overall, this is an initial release of a promising tool. And it was what I was looking for with this question in the first place.