Skip to main content
ITSIGNSolutions
Network and Firewalls

Firewall rules that look secure and are not

Any-any leftovers, shadowed rules, and objects named after people who left in 2019. A walk-through.

ITSIGN Administrator · March 5, 2025 · 2 min read

Network SecurityFirewall

We still find allow-any rules "just for the cutover" three years later. We find objects called Dave-VPN. We find shadowed denies that never fire because a broader allow sits above them.

A tidy rule count is not the same as a least-privilege policy.

What to do this quarter

Export the rule base. Mark anything unused in 90 days. Move the remaining any-any to a change ticket with an expiry. Document the business owner on the rest.

Day-to-day ownership of that estate is server and network management. A point-in-time look is a security audit.

Want this applied to your environment?

A short conversation, an honest assessment of your current setup, and a clear proposal. No obligation and no pressure.