Firewall Configuration, Hardening and Rule Audit
Many firewalls are installed once and never looked at again. Rules pile up, firmware falls behind and the admin page ends up open to the internet. We review the configuration, fix what is wrong and leave you with a firewall you can explain.
What we check
- Firmware version against the manufacturer's current supported release
- Admin access: who can sign in, from where, and whether two-step sign-in is on
- Rules that allow more than they need to, or that nothing uses any more
- Services exposed to the internet, such as remote desktop and admin pages
- Whether intrusion prevention, web filtering and anti-malware are actually applied to the rules
- VPN settings, including old encryption and shared passwords
- Logging, alerts and configuration backups
What you get
A short written report in plain language: what we found, how serious each item is, and what we changed. Changes are made in an agreed window, with a backup taken first so they can be undone.
Why it matters
Most break-ins through a firewall do not defeat it. They walk through a rule that should not exist, an admin page left reachable, or a flaw that a firmware update fixed a year earlier.
Common questions
Will the audit interrupt our internet?
The review itself does not. Changes and firmware updates can cause a short interruption, so we schedule them outside working hours.
How often should a firewall be reviewed?
Once a year is a sensible minimum, and again after any big change such as a new office, a new internet line or a move to cloud applications.
Can you audit a firewall you did not install?
Yes. We need admin access, or someone on your side who can share the screen while we go through it.