Firewall Rules Review
Analyzes and validates the security rules applied to a firewall, identifying weaknesses or misconfigured rules that could lead to a breach.

What this achieves.
Identify misconfigured rules
Highlights misconfigured firewall rules and the recommended change for each one.
Address system weaknesses
Highlights weaknesses in the firewall system configuration and recommends remediation for each finding.
How the review is done.
Each rule is reviewed against the documented business need and security best practice, using vendor security benchmarks, hardening guidelines, security research institute standards, and our own field experience.
Deliverables.
Where this connects.
Low-Level Secure Configuration Review
The same scrutiny applied to host and device configuration rather than to the rule base.
High-Level Secure Architecture Review
Reviews whether the segmentation the rules enforce was the right design in the first place.
Minimum Baseline Security Standard
Defines the configuration standard a rules review can then be measured against.
Common questions.
What is each rule checked against?
The documented business need for that rule and security best practice, drawing on vendor security benchmarks, hardening guidelines, security research institute standards, and our field experience.
Does the review cover the firewall itself, or only the rules?
Both. Alongside misconfigured rules, the review highlights weaknesses in the firewall system configuration and recommends remediation for each finding.
What do we receive at the end?
Two outputs: misconfigured rules with the recommended change for each, and firewall configuration weaknesses with their remediation guidance.
How does this relate to penetration testing?
A rules review inspects configuration against documented intent. Infrastructure Penetration Testing attempts to exploit exposure in practice. They answer different questions and are frequently scoped together.