Tighten the Edge, Rule by Rule
Firewall and Perimeter Review
We review your firewall rule bases and edge device configurations against vendor hardening guides and CIS Benchmarks. You learn which rules are too broad, which are unused, and how your perimeter really looks from outside.
See the engagement path, 6 phasesSee the full Hardening and Configuration Review service index
Overview
Firewall rule bases grow over time and rarely shrink. Old rules linger, any-any entries creep in, and management interfaces end up reachable from places they should not be. This review parses your firewall and edge configurations, checks them against vendor hardening guides and CIS Benchmarks, and pairs that with external checks of what your perimeter actually exposes. You get a clean picture of risky and redundant rules, plus a plan to tighten them safely.
Methodology
How the Engagement Runs
Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.
6 Phases, 6 Named Handovers
Flow
Flow chart of the Firewall and Perimeter Review engagement, 6 phases in order, each one selectable. Phase 1, Scoping and Baseline Selection. We list the firewalls, VPN concentrators and edge devices in scope and pick the matching CIS or vendor hardening baseline for each platform. Activities: Inventory firewalls, VPN concentrators and edge routers; Record platform, firmware version and management method; Select the CIS or vendor hardening guide per platform; Agree the external IP ranges we may probe. Hands over Device Inventory and Baseline Selection. Phase 2, Evidence and Config Collection. We collect device configurations and rule-base exports as read-only evidence, along with any network diagrams and change records you have. Activities: Collect running configurations and rule-base exports; Gather network diagrams and VLAN or zone definitions; Pull recent firewall change records and approvals; Request hit counts on rules where the platform records them. Hands over Configuration and Rule-Base Evidence Pack. Phase 3, Benchmark Comparison. We analyse configurations with Nipper and config parsers, mapping device hardening settings to CIS and vendor guides. Activities: Run Nipper against each device configuration; Parse rule bases for any-any and overly wide objects; Map device hardening settings to CIS and vendor guidance; Check management plane, SNMP and logging configuration. Hands over Device Hardening Scorecard. Phase 4, Manual Review of Risky Settings. We hand-review the rule base for overly broad, shadowed and unused rules, exposed management planes, and weak VPN and TLS settings that automated tools rank poorly. Activities: Identify shadowed, duplicated and zero-hit rules; Trace which rules permit inbound access to internal zones; Test segmentation between VLANs and trust zones; Review VPN authentication, split tunnelling and cipher settings; Check TLS on management interfaces with testssl.sh. Hands over Risky Rule and Setting Analysis. Phase 5, External Exposure Check. Using Nmap and firewalk-style probing we confirm what the perimeter actually presents from the outside, so findings reflect reality rather than intent. Activities: Scan agreed external ranges for reachable TCP and UDP services; Compare live exposure against what the rule base intends; Probe filtering behaviour with firewalk-style techniques; Confirm no management interface answers from the internet. Hands over External Exposure Evidence. Phase 6, Prioritised Findings and Re-Check. We rank findings by exposure, propose a safe rule-cleanup order, and re-review after changes to confirm the perimeter has tightened. Activities: Rank findings by external reachability and reach into the estate; Sequence rule removals from lowest to highest change risk; Draft the tightened rule wording for each change; Re-review the configuration and rescan the perimeter. Hands over Rule-Base Cleanup Plan and Re-Check Report. Each phase begins from the artefact the phase before it produced.
Phase 01 Scoping and Baseline Selection
We list the firewalls, VPN concentrators and edge devices in scope and pick the matching CIS or vendor hardening baseline for each platform.
What Happens In This Phase
- Inventory firewalls, VPN concentrators and edge routers
- Record platform, firmware version and management method
- Select the CIS or vendor hardening guide per platform
- Agree the external IP ranges we may probe
The Handover
Device Inventory and Baseline Selection
The next phase starts from this.
Phase 01 Scoping and Baseline Selection
We list the firewalls, VPN concentrators and edge devices in scope and pick the matching CIS or vendor hardening baseline for each platform.
What Happens In This Phase
- Inventory firewalls, VPN concentrators and edge routers
- Record platform, firmware version and management method
- Select the CIS or vendor hardening guide per platform
- Agree the external IP ranges we may probe
The Handover
Device Inventory and Baseline Selection
The next phase starts from this.
- 01
Scoping and Baseline Selection
We list the firewalls, VPN concentrators and edge devices in scope and pick the matching CIS or vendor hardening baseline for each platform.
OutputDevice Inventory and Baseline SelectionActivities
- Inventory firewalls, VPN concentrators and edge routers
- Record platform, firmware version and management method
- Select the CIS or vendor hardening guide per platform
- Agree the external IP ranges we may probe
- 02
Evidence and Config Collection
We collect device configurations and rule-base exports as read-only evidence, along with any network diagrams and change records you have.
OutputConfiguration and Rule-Base Evidence PackActivities
- Collect running configurations and rule-base exports
- Gather network diagrams and VLAN or zone definitions
- Pull recent firewall change records and approvals
- Request hit counts on rules where the platform records them
- 03
Benchmark Comparison
We analyse configurations with Nipper and config parsers, mapping device hardening settings to CIS and vendor guides.
OutputDevice Hardening ScorecardActivities
- Run Nipper against each device configuration
- Parse rule bases for any-any and overly wide objects
- Map device hardening settings to CIS and vendor guidance
- Check management plane, SNMP and logging configuration
- 04
Manual Review of Risky Settings
We hand-review the rule base for overly broad, shadowed and unused rules, exposed management planes, and weak VPN and TLS settings that automated tools rank poorly.
OutputRisky Rule and Setting AnalysisActivities
- Identify shadowed, duplicated and zero-hit rules
- Trace which rules permit inbound access to internal zones
- Test segmentation between VLANs and trust zones
- Review VPN authentication, split tunnelling and cipher settings
- Check TLS on management interfaces with testssl.sh
- 05
External Exposure Check
Using Nmap and firewalk-style probing we confirm what the perimeter actually presents from the outside, so findings reflect reality rather than intent.
OutputExternal Exposure EvidenceActivities
- Scan agreed external ranges for reachable TCP and UDP services
- Compare live exposure against what the rule base intends
- Probe filtering behaviour with firewalk-style techniques
- Confirm no management interface answers from the internet
- 06
Prioritised Findings and Re-Check
We rank findings by exposure, propose a safe rule-cleanup order, and re-review after changes to confirm the perimeter has tightened.
OutputRule-Base Cleanup Plan and Re-Check ReportActivities
- Rank findings by external reachability and reach into the estate
- Sequence rule removals from lowest to highest change risk
- Draft the tightened rule wording for each change
- Re-review the configuration and rescan the perimeter
Specification
What We Run, and What We Measure You Against
The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.
What Is Examined, and What it Is Measured Against
Map
Map of the Firewall and Perimeter Review scope, running left to right in three stages. Stage one, what we run, 8 tools and techniques: Nipper, Nmap, firewalk, firewall config parsers, policy-analysis tooling (AlgoSec-style review), testssl.sh, Wireshark, vendor CLI exports. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 7 published standards: CIS Cisco Benchmarks, CIS Palo Alto and Fortinet hardening references, DISA Network Infrastructure STIGs, NIST SP 800-41 (firewall policy), NIST SP 800-53, Vendor hardening guides, MITRE ATT&CK.
What We Run
8 tools
- Nipper
- firewalk
- firewall config parsers
- policy-analysis tooling (AlgoSec-style review)
- testssl.sh
- vendor CLI exports
Converges On
One Set of Proven Findings
Every issue is reproduced by hand before it is written down, and it is written down once.
Measured Against
7 standards
- CIS
- CISHardening
- DISANetwork Infrastructure
- VENDOR
Deliverables
What You Receive
- Firewall and perimeter findings report
- Rule-base cleanup plan
- Device hardening scorecard
- Re-check report after remediation
Scope This Engagement
Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.
Do you change our firewall rules?
No. We review exported configurations and give you a safe, ordered cleanup plan. Your team applies changes through your own change process.
Which firewall vendors do you cover?
We work across the common platforms, including Cisco, Palo Alto, Fortinet and Check Point, using each vendor's hardening guide alongside CIS references.
Is this the same as a penetration test?
No. This is a configuration and rule-base review. We add external checks to confirm exposure, but the focus is your edge configuration, not full exploitation.
Keep Moving Through Hardening and Configuration Review
Service 3 of 5 in this practice area
Practice Area
More in Hardening and Configuration Review
- Cloud Security Configuration AssessmentBenchmark review of your AWS, Azure and GCP accounts against secure baselines
- Operating System Hardening ReviewBenchmark comparison of your Windows and Linux builds against CIS and STIG baselines
- Active Directory and Domain Controller AuditSecurity review of your AD forest, domain controllers and privilege paths
- Database and Web Server ConfigurationHardening review of your databases and web servers against CIS Benchmarks