Firewall service

Firewall Audit & Rule Review

By the NexusSec engineering team · 8 min read · Updated July 2026
A firewall audit is a systematic review of your firewall rule base, configuration and hardening posture. Over years, rule bases accumulate temporary permissions that became permanent, rules for decommissioned systems, and overly broad "any" entries added during troubleshooting. We review the whole policy, identify what is dangerous, redundant or unused, and give you a prioritised clean-up plan you can execute safely.

Why rule bases decay

No firewall is misconfigured on day one. Decay happens gradually: an urgent request gets a temporary any-any rule at 6pm on a Friday, a project ends but its rules remain, a server is decommissioned and nobody removes its policy, staff change and the reasoning behind rules is lost.

After a few years, a typical rule base contains policies nobody can explain and nobody dares remove. That uncertainty is itself the risk — because the rules permitting an attacker's lateral movement are hiding among them.

What we review

AreaWhat we look for
Over-permissive rulesany-any policies, broad source or destination ranges, whole-subnet access where a service would do
Shadowed rulesRules never evaluated because an earlier rule already matches — a common source of false confidence
Unused rules and objectsPolicies with no hit count and objects referencing decommissioned systems
Rule orderWhether ordering produces the intended effect and whether performance can be improved
Inbound exposureServices published to the internet, especially management interfaces and remote access
Outbound controlWhether outbound traffic is filtered at all — frequently it is not, which aids data exfiltration
Segmentation policyWhether inter-zone rules genuinely restrict movement — see segmentation
Security featuresWhether IPS is blocking or merely monitoring, whether TLS inspection is enabled, whether logging is on
HardeningAdmin access controls, MFA on management, firmware currency, backup of configuration

What we typically find

Our approach

  1. Configuration collection — export of the rule base, objects, routing and feature configuration.
  2. Automated analysis — identifying shadowed, redundant, unused and over-permissive rules at scale.
  3. Manual review — assessing intent and business context, because a broad rule is sometimes legitimate.
  4. Hit-count analysis — establishing which rules are genuinely in use.
  5. Hardening review — management access, logging, feature configuration and firmware.
  6. Prioritised report — grouped into immediate risks, clean-up opportunities and architectural recommendations.
  7. Optional remediation — we can implement the changes with you in controlled windows.
We never recommend bulk-deleting rules based on hit counts alone. Some rules exist for annual processes or disaster recovery. Our method is to identify candidates, disable rather than delete, monitor for a defined period, then remove — so clean-up never causes an outage.

Platforms we audit

Fortinet FortiGate, Sophos XGS, WatchGuard Firebox, Palo Alto Networks, Check Point, Cisco, and pfSense/OPNsense. Because we deploy across all of these, recommendations are practical for your specific platform rather than generic.

How often

Annually as a baseline, and after major changes such as a network redesign, office move, merger or migration. Organisations with frequent rule changes benefit from a shorter cycle — every six months is reasonable where change volume is high.

Frequently asked questions

What is a firewall audit?

A firewall audit is a structured review of your firewall's rule base, configuration and hardening. It identifies over-permissive rules, shadowed and unused policies, unnecessary internet exposure, disabled security features, and management weaknesses, then provides a prioritised plan to fix them safely.

How do I know if my firewall rules need reviewing?

Common indicators are: rules nobody can explain, any-any entries, no documented change process, rules added during troubleshooting that were never removed, and a rule base that has never been reviewed since installation. If your firewall has been running for more than two years without a review, it almost certainly needs one.

Is it safe to delete old firewall rules?

Not without care. Some rules serve annual processes, disaster recovery or infrequent integrations, so hit counts alone can mislead. Our approach is to identify candidates, disable them rather than delete, monitor for an agreed period, and only then remove — which avoids outages while still cleaning the policy.

What is a shadowed firewall rule?

A shadowed rule is one that can never take effect because an earlier rule in the evaluation order already matches the same traffic. Shadowed rules are dangerous because administrators believe a restriction is in place when it is not being applied, creating false confidence in the policy.

Which firewall platforms do you audit?

NexusSec audits Fortinet FortiGate, Sophos XGS, WatchGuard Firebox, Palo Alto Networks, Check Point, Cisco, and pfSense/OPNsense. Because we deploy these platforms as well as audit them, our recommendations are specific and practical rather than generic best-practice statements.

When was your firewall policy last reviewed?

NexusSec audits firewall rule bases across all major platforms and helps you clean them up safely.

Request a Firewall Audit