ESSENTIAL GUIDANCE · FOUNDATION GUIDE · 5 min read

Part of Foundation insights →

Firewall configuration best practices

Practical guidance for reducing unnecessary exposure and maintaining defensible firewall rules as part of a secure operating baseline.

Firewalls remain a fundamental boundary control, but their value depends on the quality of the rules, the accuracy of the scope and the discipline used to review change. Effective hardening begins by allowing only the access the organisation can justify, then checking regularly that the live configuration still reflects that decision.

Need an acronym translated?Open the cyber glossary →

Start with the business need for every route

Document which service, user group or operational dependency requires each inbound and outbound path. A rule should identify its purpose, affected environment, accountable owner and review date. Where the reason cannot be established, investigate it before deciding whether the access can be removed safely.

Default-deny reduces accidental exposure

A default-deny approach permits only traffic that has been explicitly authorised. Keep allowed sources, destinations, ports and protocols as narrow as the service permits, and avoid broad ranges or universal sources where a more specific rule will work. Confirm the requirement with the system owner before changing production access.

Separate administration from public service access

Management interfaces should not be exposed to the public internet simply because the protected service is public. Restrict administrative access through controlled routes, strong authentication and appropriate network boundaries. Review emergency and supplier access so temporary permissions do not become permanent exceptions.

Remove obsolete and duplicated rules

Applications move, suppliers change and temporary projects end, but the related rules often remain. Review rules against current assets and service dependencies, identify duplicates and shadowed entries, and remove obsolete access through an authorised change process. Preserve enough evidence to explain what changed and why.

Treat cloud controls as part of the same boundary

Cloud security groups, network access controls, web application firewalls and platform policies can create overlapping paths. Review them together rather than assuming one control compensates for another. An apparently restricted perimeter rule may be undermined by a public cloud endpoint or a permissive identity policy.

Log what supports a decision

Firewall logs should help teams confirm expected use and investigate suspicious activity without collecting data without purpose. Define which events matter, retain them for an appropriate period and make sure monitoring teams can distinguish routine traffic from denied connections, unusual administration and unexpected changes.

Review after change and at a defined interval

Material releases, infrastructure moves, new suppliers and incident findings should trigger a targeted rule review. Periodic review remains necessary for quieter environments. Record the reviewer, evidence considered, exceptions retained and the next review date so the control can be demonstrated rather than assumed.

Validate changes and retain a recovery route

Test material rule changes through the organisation’s authorised change process before relying on them in production. Record the previous configuration, validation performed and the route for reversing the change if legitimate access is disrupted. A technically narrower rule is not an improvement if it unexpectedly prevents an essential service from operating.

Connect firewall hygiene to Cyber Essentials

Cyber Essentials includes firewalls and internet gateways among its five core control areas. Preparation requires an accurate scope and defensible configuration across relevant devices and services. Pentesys Foundation can support scope definition, readiness review and evidence preparation; it does not provide managed firewall administration.

TALK TO PENTESYS

Apply this guidance to your environment.

Tell us what you need to understand, test or prove. We'll help you choose a proportionate next step—without forcing the conversation into a predefined package.

Discuss your Cyber Essentials readiness →Explore Foundation

Keep reading

Assurance that joins up

Recognised expertise, built around your environment.

Pentesys combines independent assurance, qualified testers and practical integration with the systems your teams already use.