Network and Perimeter Security
Firewall rule bases grow and are almost never pruned. Rules added for a project that ended years ago stay in place because nobody is certain what removing them would break, and the perimeter gradually becomes more permissive than anyone intends. Managing it properly means reviewing rules as deliberately as adding them.
1
Baseline
Document what exists
2
Harden
Remove and tighten
3
Segment
Contain lateral movement
4
Access
Secure remote entry
5
Monitor
Review logs and alerts
How We Manage It
01
Baseline and Rule Review
We document the existing rule base and trace each rule to a purpose. Rules nobody can justify are candidates for removal, tested carefully rather than deleted optimistically.
- Full rule base documented with business justification
- Overly permissive and shadowed rules identified
- Unused rules flagged from hit count analysis
- Change history reconstructed where records are absent
02
Hardening and Change Control
Once the baseline is clean, changes go through a controlled process. Uncontrolled firewall change is one of the most common findings in an ICT audit and one of the easiest to fix.
- Documented change request and approval process
- Rule additions with expiry dates where temporary
- Periodic recertification of the rule base
- Configuration backup before every change
03
Network Segmentation
A flat network means one compromised workstation reaches everything. Segmentation contains that, and it matters most for the systems holding financial and personal information.
- Segmentation design separating critical systems
- Isolation of servers from general user networks
- Guest and contractor network separation
- Controls between segments documented and tested
04
Secure Remote Access
Remote access is the most attacked route into most organisations. Multi factor authentication is not optional, and access should be scoped rather than granting a full network presence.
- Multi factor authentication enforced on all remote access
- Scoped access rather than full network connectivity
- Third party and vendor access separately controlled
- Session logging and periodic access recertification
05
Monitoring and Log Review
Firewalls generate enormous log volume that nobody reads. We tune alerting to what matters and review periodically, because logs retained but never examined provide forensic value only after the fact.
- Alerting tuned to reduce noise to an actionable level
- Periodic review of blocked and permitted traffic patterns
- Log retention aligned to investigation needs
- Monthly reporting on perimeter activity and changes
What You Receive
- Documented firewall rule base with business justification
- Hardening recommendations and implemented changes
- Network segmentation design and implementation
- Multi factor authenticated remote access configuration
- Tuned alerting with defined review cadence
- Monthly reporting on perimeter activity and rule changes
Indicative Timeline
Baseline and hardening take three to five weeks depending on rule base size. Segmentation is a longer project because it needs careful testing against live traffic before enforcement.
- Baseline documentation and rule review: one to two weeks
- Hardening and change control implementation: two weeks
- Segmentation design and phased rollout: project dependent
- Ongoing management and monthly reporting
What We Manage
Perimeter and internal network controls, deployed and maintained rather than installed and forgotten.
Fortinet
We hold Fortinet partner accreditation and deploy and manage FortiGate firewalls in client environments.
Rule Base Management
Documented, justified rules with periodic recertification instead of indefinite accumulation.
Segmentation
Network separation that limits how far a single compromised device can reach.
Remote Access
Multi factor authenticated, scoped access with session logging and recertification.
Vendor Access
Third party connectivity controlled separately and removed when a contract ends.
Log Review
Tuned alerting and periodic review, so logs inform action rather than only investigation.
Frequently Asked Questions
Can you manage the firewall we already have?
Usually. Where the device is supported and not beyond end of life we manage it as it is. Replacement is proposed only where the hardware cannot support the controls you need, and we say which of the two applies.
How risky is removing old firewall rules?
It requires care, which is why we analyse hit counts first and remove in stages with rollback available. Rules with zero hits over a long period are low risk. Rules that are simply hard to explain get tested rather than deleted on assumption.
Do we really need network segmentation?
It is the single most effective control against a compromise spreading. If a workstation infection can reach your finance server directly, segmentation is worth the effort. It is also increasingly expected by insurers and auditors.
Is multi factor authentication necessary for remote access?
Yes. Credential theft is the most common route in, and remote access without a second factor means one phished password is enough. There is no configuration where we would recommend against it.
Who reviews the firewall logs?
We do, on an agreed cadence, with alerting tuned so genuine events are visible. Nobody reads raw firewall logs continuously, which is why tuning matters more than collection.
Does this cover our cloud environments?
Cloud network controls follow the same principles but different tooling. Where you run hybrid we cover both, since a well managed perimeter with an exposed cloud storage bucket behind it achieves very little.
Related Services
This sits inside our Managed ICT Services practice. Related work: Vulnerability Assessments to verify the perimeter independently, and Penetration Testing to establish what an attacker could actually reach through it.
