// FIREWALL REVIEW · HANS STUDY · ONTARIO, CANADA
Firewall review
A rule base nobody has read end to end since it was first built, on a firewall protecting a network, a server room, or a security-system segment. This review reads it, checks it against what the firewall is actually supposed to be doing, and hands back a ranked list of what to fix.
What it covers
Rule-by-rule review of the policy base: unused and shadowed rules, overly broad "any/any" entries, NAT and port-forward exposure, logging configuration, administrative access controls, firmware and licence status, and segmentation between zones the firewall is meant to separate. The review works from an export of the configuration and a short conversation about what each segment is for, since a rule that looks wrong on its own is sometimes exactly what the network needs.
After the changes go in, PortProof, a free PowerShell script, checks that the paths you still need are open and the ones you closed are closed.
What you receive
- A findings report ranked by consequence, not by rule count
- A plain list of what to change first, second, and later
- Notes on anything that needs a conversation with your integrator or vendor before it changes
Questions
What do I need to send before a firewall review?
An export of the firewall configuration, and a short conversation about what each segment is for. A short scoping call confirms the firewall model, the export format, and the scope.
What does a firewall review check?
Unused and shadowed rules, overly broad any/any entries, NAT and port-forward exposure, logging configuration, administrative access controls, firmware and licence status, and segmentation between zones the firewall is meant to separate.
Is it one firewall or the whole network?
A review covers one firewall or HA pair. For segmentation, switch configurations, and remote access across the whole network, see the network security assessment.
Can the review be done remotely?
Yes. It works from a configuration export, and it's delivered remotely, or through the DHD, a remote access device shipped to site.
How do I check the changes after they go in?
PortProof, a free PowerShell script, checks that the paths you still need are open and the ones you closed are closed.
How much does a firewall review cost?
The firewall model, export format, and scope are confirmed on a scoping call, and a written quote comes before any work starts.
Book a scoping call
A short call confirms the firewall model, the export format, and the scope.
Delivered remotely, or through the DHD, a remote access device shipped to site.