Firewall Rules Somebody Can Still Read Next Year
FortiGate, Palo Alto, MikroTik and Cisco, built from scratch or cleaned up after whoever had them last. Policy written in an order that makes sense, management access taken off the public internet, high availability pairs that actually fail over when tested, and multi site VPN that holds together when a link drops.
Most firewalls do not fail because the hardware was wrong. They fail because five years of exceptions piled up, nobody wrote down why any of them exist, and the person who understood the box left. That is the state we usually find them in, and it is the state we make sure yours is not left in.
What The Work Covers
Six kinds of job, and most engagements are one or two of them rather than all six. A new firewall out of the box and a ten year old rule set that nobody dares touch are very different pieces of work, so the first conversation is mostly about which of these you are actually looking at.
A New Firewall Configured Properly
Interfaces, zones, routing, address translation and a policy set written in an order that still makes sense when somebody adds to it later. Naming conventions applied from the first rule, because that is the part nobody retrofits once there are two hundred entries.
A Rule Set Nobody Understands Any More
Rules that have never matched a packet, duplicates, entries shadowed by something broader above them, and objects pointing at servers that were decommissioned years ago. Everything removed gets listed with the reason, so you approve the deletions rather than trusting a summary.
Management Access Off The Internet
Administrative interfaces reachable only from where they should be, default accounts dealt with, logging pointed somewhere it survives a reboot, and firmware brought current. Most firewall compromises start at the management interface rather than at a rule.
High Availability Pairs, Tested Rather Than Assumed
Two devices configured as a pair, with the heartbeat links and session sync set up correctly. Then we pull the cable and watch what happens, because plenty of pairs sit in production for years having never once failed over successfully.
Moving From One Vendor To Another
Cisco to FortiGate, MikroTik to Palo Alto, or a straight hardware refresh. Rules translated by hand rather than by a conversion tool, because the automatic ones carry over the mess along with the policy and leave you paying for new hardware to run the old problem.
Several Offices Joined Together
Hub and spoke or full mesh, with routing that reconverges when a link drops instead of leaving one branch stranded. Mixed vendors on either end are normal here, and the settings sheet covering both sides is part of what gets handed back.
The Platforms We Work On
Four vendors, and the differences between them matter more in the interface than in the capability. Anything else running a standard feature set is worth asking about.
- FortiGate. Policy sets, SD-WAN, IPsec tunnels, HA clusters and the FortiOS upgrade path when a version jump is involved.
- Palo Alto. Security rules across zones, App-ID policy, IKE and IPsec crypto profiles, and the tunnel interfaces that sit behind them.
- MikroTik. RouterOS firewall chains, address lists, IPsec and WireGuard, and the raw and mangle rules that quietly interfere with everything else.
- Cisco. ASA and Firepower policy, access lists, NAT statements and site to site tunnels, plus IOS router firewalling where that is what you have.
How A Job Runs On A Live Network
The risk on firewall work is never the configuration, it is the timing. Everything below exists so that a change goes in when you are ready for it and comes back out just as quickly if something behaves unexpectedly.
We Read It Before Touching Anything
A configuration export or read only access, plus whatever documentation exists even if it is out of date. On a rule set that has grown for years this stage is most of the job, because working out what each entry is for takes longer than changing any of them.
You See The Plan Before It Is Applied
What is going in, what is coming out, and what each removal was originally there for. Anything we are unsure about stays in place and gets flagged rather than deleted quietly, because the rule nobody remembers is occasionally the one holding up a payment system.
Changes Go In Inside A Window You Pick
The running configuration is saved first so there is always a way back, and changes go in a few at a time rather than as one large edit that has to be unpicked if something stops working. On a pair, one device at a time with the failover tested between them.
Traffic Gets Checked, Not Assumed
The applications that matter to you tested from the networks they are used on, in both directions, before the window closes. A firewall that accepted the configuration has told you very little, and this is the step that separates finished from probably fine.
You Keep The Documentation
What the rules do, why the exceptions exist, and the short procedures for the changes you will make yourself. Written so that whoever inherits the firewall after you can read it, which is the thing that stops the whole cycle starting again in three years.
What You Get At The End
- The finished configuration, backed up and handed to you.
- A rule set document explaining what each policy group is for.
- A list of what was removed and why, with anything uncertain kept.
- The test results, per application and per direction.
- A note of anything working by accident that will break later.
What Sits Outside This
- Hardware supply. We do not sell it and take nothing from what you buy.
- Vendor support cases, which stay under your own contract even when we prepare one.
- Licence renewals and subscription features, which are yours to hold.
- Ongoing management, available as a separate arrangement rather than assumed.
Tell Us What You Have And What Needs Doing
The vendor, roughly how many sites are involved, and whether this is a new build, a clean up, a migration or something that stopped working. Send a configuration export with it and you will get our reading of the state it is in before there is a quote to consider. Nothing changes on a live network until you have picked the window.
Talk about your firewall