Skip to main content
REF-INF-002

Firewall Rules Review

Analyzes and validates the security rules applied to a firewall, identifying weaknesses or misconfigured rules that could lead to a breach.

Close view of a firewall appliance port panel
Objectives

What this achieves.

01

Identify misconfigured rules

Highlights misconfigured firewall rules and the recommended change for each one.

02

Address system weaknesses

Highlights weaknesses in the firewall system configuration and recommends remediation for each finding.

Approach

How the review is done.

Each rule is reviewed against the documented business need and security best practice, using vendor security benchmarks, hardening guidelines, security research institute standards, and our own field experience.

Deliverables.

Misconfigured rules & recommended changes
Firewall configuration weaknesses & remediation
FAQ

Common questions.

What is each rule checked against?

The documented business need for that rule and security best practice, drawing on vendor security benchmarks, hardening guidelines, security research institute standards, and our field experience.

Does the review cover the firewall itself, or only the rules?

Both. Alongside misconfigured rules, the review highlights weaknesses in the firewall system configuration and recommends remediation for each finding.

What do we receive at the end?

Two outputs: misconfigured rules with the recommended change for each, and firewall configuration weaknesses with their remediation guidance.

How does this relate to penetration testing?

A rules review inspects configuration against documented intent. Infrastructure Penetration Testing attempts to exploit exposure in practice. They answer different questions and are frequently scoped together.

Ready to scope Firewall Rules Review?

Request an Assessment
Request an Assessment Email Us