Firewall audit · Operating since 2002
Every firewall estate accumulates rules faster than it retires them. Someone opens a port for a project that ended in 2019, the ticket closes, and the rule stays. A firewall audit reads the configuration you are actually running and tells you which rules carry traffic, which are shadowed by rules above them, which are duplicates, and which quietly permit far more than anyone intended.
Vendor-neutral review · FortiGate, Cisco, Palo Alto, Check Point, Sophos, SonicWall
The review
What a firewall audit actually inspects
A real audit is not a vulnerability scan pointed at the outside interface. It is a read of the configuration, the objects behind it, and the logs that show what the rules do in practice.
The rule base
Rule-by-rule review for shadowing, duplication, permissive any-any entries, rules with no hit count, and ordering that silently defeats a control further down the list.
- Shadowed and unreachable rules
- Any-any and any-service entries
- Zero-hit rules and stale exceptions
- Ordering and precedence defects
Objects and groups
The address objects, service definitions and nested groups that rules resolve to. This is where a tidy-looking rule base hides an object group that quietly grew to include half the internal network.
- Over-broad address objects
- Nested group sprawl
- Orphaned and unused objects
Administrative access
Who can change the firewall, from where, with what authentication, and whether those changes are logged in a way that survives the person who made them leaving.
- Admin account inventory
- Management-plane exposure
- Change logging and retention
Logging and retention
Whether the firewall is logging the traffic you would need during an incident, whether those logs leave the box, and whether they are retained where you can actually query them.
- Log completeness by rule
- Off-box forwarding
- Retention and query path
High availability and firmware
HA sync state, failover behaviour that has often never been tested under load, firmware currency, and whether the pair would genuinely survive losing the active unit.
- HA sync and split-brain risk
- Firmware and known-issue review
- Failover test findings
The written report
Findings ranked by exposure, each with the specific change that closes it, written so your own team or any other provider can act on it without us.
- Ranked findings
- Change-by-change remediation
- Readable by whoever runs it next
Why this happens
Why rule bases decay
Nothing about firewall decay is anyone’s fault. It is a structural consequence of how change requests work: opening a rule is a five-minute task with an obvious requester, and closing one is an unowned task with no requester at all. Over a few years the arithmetic only ever runs one way.
The gap between the config and the traffic is the finding.
The practical consequence is that the firewall stops being a statement of policy and becomes an archaeological record. That matters at audit time, but it matters more during an incident, when the question “could this have reached that?” needs an answer in minutes and the rule base cannot give one.
Scope and price
What you get, and what it costs
Configuration audit starts at ₹25,000. Beyond that the price is driven by scope, and we scope from a configuration export rather than a user count — a thousand users behind twelve simple rules is a smaller job than eighty users behind nine hundred.
| What drives the price | Why it matters | What we ask for |
|---|---|---|
| Enforcement points | Each firewall pair is a separate rule base with its own history, even when the policy is meant to be identical. | How many pairs, and are they meant to match |
| Rule-base size | Review effort tracks rule count and object nesting far more closely than it tracks user count or bandwidth. | A sanitised config export |
| Log availability | Hit counts separate a live rule from a dead one. Without logs the audit can still find shadowing and permissiveness, but not disuse. | A representative log sample |
| Remediation | Documenting a fix and carrying it out are different jobs. We quote them separately so the report stays independent. | Whether you want the changes made |
Scroll the table sideways on a narrow screen.
We do not quote a firewall audit from a user count alone. Send a config export and the number stops being a guess.
After the report
Where an audit usually leads
An audit is a diagnostic, and diagnostics are only worth commissioning if you are prepared to act on the result. In practice the findings point at one of four pieces of work.
Rule-base remediation
Removing what is dead and tightening what is over-broad, in change windows, with a rollback position at every step.
Platform migration
Sometimes the rule base is not salvageable and a clean rebuild on new hardware is cheaper than the cleanup. See firewall migration services.
Ongoing management
Rule bases decay because nobody owns retirement. A managed service that owns it is the only durable fix. See firewall services.
Maintenance cover
If the finding is stale firmware and untested failover, that is an AMC question rather than a rule question.
Questions
Firewall audit, answered
What is a firewall audit?
A structured review of what your firewall is actually configured to do, as opposed to what everyone believes it does. It covers the rule base, the objects and groups behind it, administrative access, logging, high-availability state and firmware. The output is a ranked list of findings with the change needed for each, not a tool dump.
How is this different from a VAPT or penetration test?
A penetration test attacks the outside of the estate and tells you what an attacker can reach. An audit reads the configuration from the inside and tells you why. They answer different questions and the findings rarely overlap. Most estates need both, and the audit is usually the cheaper one to act on. See our VAPT services.
How long does a firewall audit take?
For a single pair of firewalls with a few hundred rules, the review is typically a few days once we have the configuration and a log sample. Large multi-site estates take longer, and the variable is almost never the reading — it is how long it takes to find someone who can explain why a given rule exists.
Do you need access to our firewalls?
No. A sanitised configuration export and a representative log sample are enough for the review itself. Read-only access helps us confirm live state such as session counts and HA sync, but it is optional and we are equally happy working from exports under NDA.
What does a firewall audit cost?
Configuration audit starts at ₹25,000. The real drivers are the number of enforcement points, the size of the rule base and whether you need the remediation carried out as well as documented. We scope from a config export rather than a user count, because a user count tells us nothing about rule-base complexity.
Will you also fix what you find?
Yes, as a separate piece of work, and deliberately so. The audit has to be able to say uncomfortable things, which is easier when it is not a sales document for the remediation. If you want the fixes carried out we quote them separately and you are free to hand the report to anyone else.
Which firewall platforms do you audit?
FortiGate, Cisco ASA and Firepower, Palo Alto, Check Point, Sophos and SonicWall. We are a Fortinet partner with NSE-certified engineers, so FortiGate estates get the deepest review, but the audit method is vendor-neutral and the report is written to be readable by whoever runs the box next.
Next step
Get your rule base read by someone who did not write it
Send a sanitised configuration export and we will tell you what the audit would cover and what it would cost. If the rule base turns out to be in good order we will say so.



