Skip to content
ISO 27001, SOC 2, the DPDP Act and manual VAPT.
Part of Hardening and Configuration Review5 services in this practice area

Tighten the Edge, Rule by Rule

Firewall and Perimeter Review

We review your firewall rule bases and edge device configurations against vendor hardening guides and CIS Benchmarks. You learn which rules are too broad, which are unused, and how your perimeter really looks from outside.

See the engagement path, 6 phasesSee the full Hardening and Configuration Review service index

Overview

Firewall rule bases grow over time and rarely shrink. Old rules linger, any-any entries creep in, and management interfaces end up reachable from places they should not be. This review parses your firewall and edge configurations, checks them against vendor hardening guides and CIS Benchmarks, and pairs that with external checks of what your perimeter actually exposes. You get a clean picture of risky and redundant rules, plus a plan to tighten them safely.

Methodology

How the Engagement Runs

Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.

The Engagement, End to End

6 Phases, 6 Named Handovers

Flow

Flow chart of the Firewall and Perimeter Review engagement, 6 phases in order, each one selectable. Phase 1, Scoping and Baseline Selection. We list the firewalls, VPN concentrators and edge devices in scope and pick the matching CIS or vendor hardening baseline for each platform. Activities: Inventory firewalls, VPN concentrators and edge routers; Record platform, firmware version and management method; Select the CIS or vendor hardening guide per platform; Agree the external IP ranges we may probe. Hands over Device Inventory and Baseline Selection. Phase 2, Evidence and Config Collection. We collect device configurations and rule-base exports as read-only evidence, along with any network diagrams and change records you have. Activities: Collect running configurations and rule-base exports; Gather network diagrams and VLAN or zone definitions; Pull recent firewall change records and approvals; Request hit counts on rules where the platform records them. Hands over Configuration and Rule-Base Evidence Pack. Phase 3, Benchmark Comparison. We analyse configurations with Nipper and config parsers, mapping device hardening settings to CIS and vendor guides. Activities: Run Nipper against each device configuration; Parse rule bases for any-any and overly wide objects; Map device hardening settings to CIS and vendor guidance; Check management plane, SNMP and logging configuration. Hands over Device Hardening Scorecard. Phase 4, Manual Review of Risky Settings. We hand-review the rule base for overly broad, shadowed and unused rules, exposed management planes, and weak VPN and TLS settings that automated tools rank poorly. Activities: Identify shadowed, duplicated and zero-hit rules; Trace which rules permit inbound access to internal zones; Test segmentation between VLANs and trust zones; Review VPN authentication, split tunnelling and cipher settings; Check TLS on management interfaces with testssl.sh. Hands over Risky Rule and Setting Analysis. Phase 5, External Exposure Check. Using Nmap and firewalk-style probing we confirm what the perimeter actually presents from the outside, so findings reflect reality rather than intent. Activities: Scan agreed external ranges for reachable TCP and UDP services; Compare live exposure against what the rule base intends; Probe filtering behaviour with firewalk-style techniques; Confirm no management interface answers from the internet. Hands over External Exposure Evidence. Phase 6, Prioritised Findings and Re-Check. We rank findings by exposure, propose a safe rule-cleanup order, and re-review after changes to confirm the perimeter has tightened. Activities: Rank findings by external reachability and reach into the estate; Sequence rule removals from lowest to highest change risk; Draft the tightened rule wording for each change; Re-review the configuration and rescan the perimeter. Hands over Rule-Base Cleanup Plan and Re-Check Report. Each phase begins from the artefact the phase before it produced.

Phase 01 Scoping and Baseline Selection

We list the firewalls, VPN concentrators and edge devices in scope and pick the matching CIS or vendor hardening baseline for each platform.

What Happens In This Phase

  • Inventory firewalls, VPN concentrators and edge routers
  • Record platform, firmware version and management method
  • Select the CIS or vendor hardening guide per platform
  • Agree the external IP ranges we may probe

The Handover

Device Inventory and Baseline Selection

The next phase starts from this.

Read the handover cards on their own and you have the paper trail. Select a phase to see what happens inside it.
  1. 01

    Scoping and Baseline Selection

    We list the firewalls, VPN concentrators and edge devices in scope and pick the matching CIS or vendor hardening baseline for each platform.

    OutputDevice Inventory and Baseline Selection

    Activities

    • Inventory firewalls, VPN concentrators and edge routers
    • Record platform, firmware version and management method
    • Select the CIS or vendor hardening guide per platform
    • Agree the external IP ranges we may probe
  2. 02

    Evidence and Config Collection

    We collect device configurations and rule-base exports as read-only evidence, along with any network diagrams and change records you have.

    OutputConfiguration and Rule-Base Evidence Pack

    Activities

    • Collect running configurations and rule-base exports
    • Gather network diagrams and VLAN or zone definitions
    • Pull recent firewall change records and approvals
    • Request hit counts on rules where the platform records them
  3. 03

    Benchmark Comparison

    We analyse configurations with Nipper and config parsers, mapping device hardening settings to CIS and vendor guides.

    OutputDevice Hardening Scorecard

    Activities

    • Run Nipper against each device configuration
    • Parse rule bases for any-any and overly wide objects
    • Map device hardening settings to CIS and vendor guidance
    • Check management plane, SNMP and logging configuration
  4. 04

    Manual Review of Risky Settings

    We hand-review the rule base for overly broad, shadowed and unused rules, exposed management planes, and weak VPN and TLS settings that automated tools rank poorly.

    OutputRisky Rule and Setting Analysis

    Activities

    • Identify shadowed, duplicated and zero-hit rules
    • Trace which rules permit inbound access to internal zones
    • Test segmentation between VLANs and trust zones
    • Review VPN authentication, split tunnelling and cipher settings
    • Check TLS on management interfaces with testssl.sh
  5. 05

    External Exposure Check

    Using Nmap and firewalk-style probing we confirm what the perimeter actually presents from the outside, so findings reflect reality rather than intent.

    OutputExternal Exposure Evidence

    Activities

    • Scan agreed external ranges for reachable TCP and UDP services
    • Compare live exposure against what the rule base intends
    • Probe filtering behaviour with firewalk-style techniques
    • Confirm no management interface answers from the internet
  6. 06

    Prioritised Findings and Re-Check

    We rank findings by exposure, propose a safe rule-cleanup order, and re-review after changes to confirm the perimeter has tightened.

    OutputRule-Base Cleanup Plan and Re-Check Report

    Activities

    • Rank findings by external reachability and reach into the estate
    • Sequence rule removals from lowest to highest change risk
    • Draft the tightened rule wording for each change
    • Re-review the configuration and rescan the perimeter

Specification

What We Run, and What We Measure You Against

The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.

Scope

What Is Examined, and What it Is Measured Against

Map

Map of the Firewall and Perimeter Review scope, running left to right in three stages. Stage one, what we run, 8 tools and techniques: Nipper, Nmap, firewalk, firewall config parsers, policy-analysis tooling (AlgoSec-style review), testssl.sh, Wireshark, vendor CLI exports. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 7 published standards: CIS Cisco Benchmarks, CIS Palo Alto and Fortinet hardening references, DISA Network Infrastructure STIGs, NIST SP 800-41 (firewall policy), NIST SP 800-53, Vendor hardening guides, MITRE ATT&CK.

What We Run

8 tools

  • Nipper
  • Nmap
  • firewalk
  • firewall config parsers
  • policy-analysis tooling (AlgoSec-style review)
  • testssl.sh
  • Wireshark
  • vendor CLI exports

Converges On

One Set of Proven Findings

Every issue is reproduced by hand before it is written down, and it is written down once.

Measured Against

7 standards

  • CISCisco
  • CISPalo Alto and FortinetHardening
  • DISASTIGsNetwork Infrastructure
  • NIST SP 800-41 (firewall policy)
  • NIST SP 800-53
  • VENDORHardening Guides
  • MITRE ATT&CK
One pass of testing and analysis, one set of findings, then that single set is graded against every standard on the right. You are not paying for the same work once per framework.

Deliverables

What You Receive

  • Firewall and perimeter findings report
  • Rule-base cleanup plan
  • Device hardening scorecard
  • Re-check report after remediation

Scope This Engagement

Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.

Questions

What Clients Ask Us

Something here not covered? Ask Us Directly.

Do you change our firewall rules?

No. We review exported configurations and give you a safe, ordered cleanup plan. Your team applies changes through your own change process.

Which firewall vendors do you cover?

We work across the common platforms, including Cisco, Palo Alto, Fortinet and Check Point, using each vendor's hardening guide alongside CIS references.

Is this the same as a penetration test?

No. This is a configuration and rule-base review. We add external checks to confirm exposure, but the focus is your edge configuration, not full exploitation.