Skip to content
Vaptiq logo mark — V orientationVAPTIQ
All services

[ Infrastructure ]

Firewall Configuration Review

Rule-by-rule audit of your firewall estate: what is open, to whom, and why.
Typical duration
3-5 days
Starting price
Scoped
You provide
Read-only access to firewall configurations

[ 01 / The engagement ]

Most firewall rulebases grow one ticket at a time and nobody ever removes anything. We pull every rule, object and NAT statement, map the effective access paths, and flag the rules that are too broad, too old, or too dangerous to leave in place. The deliverable is a clean, prioritised list of changes your network team can action immediately.

[ 02 / Coverage ]

What we test, in practice.

This is the working checklist, not a marketing list. Anything your scope adds gets written into the engagement letter before we start.

Methodology

CIS BenchmarksNIST SP 800-41PCI DSS
  1. 01Full rulebase audit across every firewall in scope
  2. 02Shadowed, redundant and expired rule identification
  3. 03Overly permissive any-to-any and any-source rules
  4. 04Insecure management access and SNMP exposure
  5. 05NAT and PAT rule review for unintended exposure
  6. 06VPN configuration, cipher strength and split-tunnelling review
  7. 07Rule ordering analysis and optimisation recommendations

[ 03 / What you get ]

Four things land at the end of every engagement.

Technical report

Every finding with CVSS v4.0 score, evidence, reproduction steps and a specific fix, written for the engineer who has to close it.

Executive summary

Two pages your board can read. Risk in business terms, with the three things that matter most called out.

Letter of attestation

A shareable document proving the test happened and what it covered, for customers and auditors who should not see the full report.

Free retest

Once you have fixed things, the same tester verifies each finding and reissues the report. Included for 90 days.

[ 04 / Questions ]

Before you commit.

Palo Alto, Fortinet, Check Point, Cisco ASA and Firepower, Juniper SRX, pfSense and cloud-native firewalls in AWS, Azure and GCP. If yours is not listed, ask, we have probably worked with it.

Read-only access to the running configuration is enough. We do not make changes, and we can work from a configuration export if policy prevents live access.

Scope a firewall configuration review.

Send us the target and the deadline. You get a written scope and a fixed price, usually within one working day.