Firewall rules that look secure and are not
Any-any leftovers, shadowed rules, and objects named after people who left in 2019. A walk-through.
ITSIGN Administrator · March 5, 2025 · 2 min read
We still find allow-any rules "just for the cutover" three years later. We find objects called Dave-VPN. We find shadowed denies that never fire because a broader allow sits above them.
A tidy rule count is not the same as a least-privilege policy.
What to do this quarter
Export the rule base. Mark anything unused in 90 days. Move the remaining any-any to a change ticket with an expiry. Document the business owner on the rest.
Day-to-day ownership of that estate is server and network management. A point-in-time look is a security audit.
Related reading
Do you still need a perimeter firewall?
Yes, if you have an office. No, it is not your only control. Identity is the new edge, and both still matter.
2 min read
Site-to-site VPN mistakes we still walk into
Overlapping subnets, stale tunnels, and a second office that was never documented.
2 min read
Firewall change control that people will actually follow
If the process takes a week, someone will bypass it on a Friday. Make it short and recorded.
2 min read
Want this applied to your environment?
A short conversation, an honest assessment of your current setup, and a clear proposal. No obligation and no pressure.
