[ Infrastructure ]
Firewall Configuration Review
- Typical duration
- 3-5 days
- Starting price
- Scoped
- You provide
- Read-only access to firewall configurations
[ 01 / The engagement ]
Most firewall rulebases grow one ticket at a time and nobody ever removes anything. We pull every rule, object and NAT statement, map the effective access paths, and flag the rules that are too broad, too old, or too dangerous to leave in place. The deliverable is a clean, prioritised list of changes your network team can action immediately.
[ 02 / Coverage ]
What we test, in practice.
This is the working checklist, not a marketing list. Anything your scope adds gets written into the engagement letter before we start.
Methodology
- 01Full rulebase audit across every firewall in scope
- 02Shadowed, redundant and expired rule identification
- 03Overly permissive any-to-any and any-source rules
- 04Insecure management access and SNMP exposure
- 05NAT and PAT rule review for unintended exposure
- 06VPN configuration, cipher strength and split-tunnelling review
- 07Rule ordering analysis and optimisation recommendations
[ 03 / What you get ]
Four things land at the end of every engagement.
Technical report
Every finding with CVSS v4.0 score, evidence, reproduction steps and a specific fix, written for the engineer who has to close it.
Executive summary
Two pages your board can read. Risk in business terms, with the three things that matter most called out.
Letter of attestation
A shareable document proving the test happened and what it covered, for customers and auditors who should not see the full report.
Free retest
Once you have fixed things, the same tester verifies each finding and reissues the report. Included for 90 days.
[ 04 / Questions ]
Before you commit.
Palo Alto, Fortinet, Check Point, Cisco ASA and Firepower, Juniper SRX, pfSense and cloud-native firewalls in AWS, Azure and GCP. If yours is not listed, ask, we have probably worked with it.
Read-only access to the running configuration is enough. We do not make changes, and we can work from a configuration export if policy prevents live access.
Often scoped together
All services →External Network Penetration Testing
Everything of yours that answers from the internet, including what you forgot.
Internal Network Penetration Testing
We assume the perimeter already failed, and see how far one foothold travels.
Active Directory Security Assessment
The attack paths from any user to Domain Admin, mapped and proven.
Scope a firewall configuration review.
Send us the target and the deadline. You get a written scope and a fixed price, usually within one working day.