Reviewing firewall rules
Recently, the guys at matasano have released Flint, a firewall rules checker. It's GPL and runs on sinatra.
(source: runplaybook.com)
Looks very promising. Although I haven't tried it yet. There's only support for PIX/ASA firewalls, but they will be adding others in the future.
EDIT:
I have installed it and tested it. Installation is very simple. As for the analysis, I fed it with a complex firewall configuration and it took a long time to analyze. Results were mostly correct, but there were parsing errors.
Overall, this is an initial release of a promising tool. And it was what I was looking for with this question in the first place.