• SituationAging perimeter · large rule set · single device · tribal knowledge gone
  • RiskUnknown exposure · outage if the box failed · no audit-ready explanation
  • OutcomeHygiene’d policy · HA design · documented change process someone can operate

The situation

Traffic still flowed. Tickets still got closed with “opened port 443.” Over years that produces a rule base that is easy to add to and hard to trust. Shadow IT paths, temporary exceptions that never expired, and VPN configs that predated current identity practices all lived in the same policy.

Buying a new firewall without cleaning the policy only migrates the mess. The engagement started with understanding what was actually required — not what the rule list claimed.

What we did

  • Full export and review of the existing rule set against real traffic and application owners
  • Removal or tightening of dead, duplicate, and overly broad rules
  • High-availability design and cutover plan so a single appliance was no longer a single point of failure
  • Site-to-site and remote-access VPN reviewed against current needs (not “how it was in 2019”)
  • Change-control expectations and an operational runbook for the people left holding the pager
  • Baseline monitoring so policy and device health were not invisible until something broke

Results

The firm ended with a smaller, documented policy that matched real business needs, resilient perimeter design, and a written picture of what remains intentional. Leadership could answer “who can reach what?” without archaeology.

Client identity is withheld by agreement. The pattern is one we repeat: clean and own the perimeter before you decorate it with more tools.

Related

See our Network Security practice, or contact us if your firewall is “working” but nobody wants to touch it.

Ready to talk through the next step?

Projects, managed services, or an honest read on your environment. You reach a principal consultant.