Firewall & Configuration Review
Review security-relevant configurations to identify unnecessary exposure, weak access controls and configuration risks.
A firewall rule base is a historical record. Rules are added under pressure during incidents and migrations, and removing one later means being confident it is unused — which is difficult to prove. So rules accumulate, and the effective policy stops matching the intended one.
A configuration review reads that policy as it actually stands: what is permitted, what is exposed, what is no longer needed, and where segmentation exists on the diagram but not in the rule base.
Rules are easy to add and hard to remove
Every rule was added for a reason. The reason is rarely documented, the person who added it may have moved on, and nobody wants to be responsible for removing the rule that turns out to be load-bearing.
The result is a policy that grows monotonically: broad rules that were meant to be temporary, permitted paths for systems that no longer exist, and administrative access reachable from more places than anyone intends.
The layers this assessment covers.
| RULE | SOURCE | DESTINATION | SERVICE | ACTION | REVIEW |
|---|---|---|---|---|---|
| 001 | ANY | DMZ-WEB | HTTPS/443 | ALLOW | EXPECTED |
| 014 | CORP-LAN | DB-TIER | SQL/1433 | ALLOW | REVIEW |
| 027 | ANY | MGMT-NET | SSH/22 | ALLOW | FLAG |
| 041 | PARTNER | APP-TIER | ANY | ALLOW | FLAG |
| 058 | CORP-LAN | ANY | ANY | ALLOW | FLAG |
| 072 | DMZ-WEB | DB-TIER | SQL/1433 | ALLOW | EXPECTED |
| 089 | LEGACY-VLAN | ANY | ANY | ALLOW | REVIEW |
Each boundary should narrow what passes. A review establishes whether it does.
- INTERNETInternetEverything that can reach the perimeter
- FIREWALLFirewallThe rule base, and what it permits in practice
- NETWORKNetworkSegmentation between zones and environments
- SERVICESServicesWhat is reachable once inside a zone
- CRITICALCritical systemsSystems whose exposure carries real impact
Conceptual view of a layered network. Review scope depends on the environment and the configurations provided.
What we review
Review is performed against configurations you provide for the devices in scope.
How a configuration review runs
- 01COLLECTObtain configurations for the devices in scope.
- 02BASELINEEstablish intended policy and the zones it is meant to separate.
- 03ANALYSERead the effective policy and identify where it diverges.
- 04EXPOSUREIdentify unnecessary exposure and overly broad permissions.
- 05PRIORITISERank findings by what they would actually allow.
- 06REPORTFindings with specific, actionable remediation guidance.
When Should the Rule Base Be Read Properly?
Findings your team can act on.
Which of these apply depends on engagement scope.
Weaknesses identified across the environment in scope, with the reasoning behind each.
Settings that widen exposure or weaken a boundary, described precisely enough to locate.
What a finding means in your environment rather than against a generic scoring table.
Supporting detail so findings can be verified rather than taken on trust.
Practical direction on addressing each finding, including where the change belongs.
An order of work, so limited engineering time goes to what matters most.
Verification that addressed findings no longer reproduce, within the agreed retest scope.
Adjacent parts of the infrastructure.
Questions we get asked before an engagement.
Configuration exports for the devices in scope, plus context on intended zones and which systems matter most. The context is what turns a rule listing into a risk assessment.
No. A review reads the configuration directly, which finds things testing would miss — redundant rules, shadowed rules, permitted paths nobody exercises. Testing shows what is reachable in practice. They complement each other.
Where in scope. Security groups, network ACLs and cloud routing are the same class of problem, and in hybrid environments the interesting gaps are often at the join between the two.
We identify rules that appear redundant or overly broad, with the reasoning. The decision to remove stays with your team, since only you can confirm what is genuinely unused.
Request a Configuration Review
Send us the shape of the environment — the zones you intend to separate and the systems that matter most.
