Firewall Audit & Rule Review Services India

  • Home
  • Firewall Audit & Rule Review Services India
Firewall Audit & Rule Review Services India
Firewall Audit & Rule Review Services India
Firewall Audit & Rule Review Services India
Firewall Audit & Rule Review Services India

Firewall audit · Operating since 2002

Firewall audit and rule reviewMost rule bases are a decade of undocumented exceptions. An audit is how you find out which ones still matter.

Every firewall estate accumulates rules faster than it retires them. Someone opens a port for a project that ended in 2019, the ticket closes, and the rule stays. A firewall audit reads the configuration you are actually running and tells you which rules carry traffic, which are shadowed by rules above them, which are duplicates, and which quietly permit far more than anyone intended.

Vendor-neutral review · FortiGate, Cisco, Palo Alto, Check Point, Sophos, SonicWall

The review

What a firewall audit actually inspects

A real audit is not a vulnerability scan pointed at the outside interface. It is a read of the configuration, the objects behind it, and the logs that show what the rules do in practice.

01

The rule base

Rule-by-rule review for shadowing, duplication, permissive any-any entries, rules with no hit count, and ordering that silently defeats a control further down the list.

  • Shadowed and unreachable rules
  • Any-any and any-service entries
  • Zero-hit rules and stale exceptions
  • Ordering and precedence defects
02

Objects and groups

The address objects, service definitions and nested groups that rules resolve to. This is where a tidy-looking rule base hides an object group that quietly grew to include half the internal network.

  • Over-broad address objects
  • Nested group sprawl
  • Orphaned and unused objects
03

Administrative access

Who can change the firewall, from where, with what authentication, and whether those changes are logged in a way that survives the person who made them leaving.

  • Admin account inventory
  • Management-plane exposure
  • Change logging and retention
04

Logging and retention

Whether the firewall is logging the traffic you would need during an incident, whether those logs leave the box, and whether they are retained where you can actually query them.

  • Log completeness by rule
  • Off-box forwarding
  • Retention and query path
05

High availability and firmware

HA sync state, failover behaviour that has often never been tested under load, firmware currency, and whether the pair would genuinely survive losing the active unit.

  • HA sync and split-brain risk
  • Firmware and known-issue review
  • Failover test findings
06

The written report

Findings ranked by exposure, each with the specific change that closes it, written so your own team or any other provider can act on it without us.

  • Ranked findings
  • Change-by-change remediation
  • Readable by whoever runs it next

Why this happens

Why rule bases decay

Nothing about firewall decay is anyone’s fault. It is a structural consequence of how change requests work: opening a rule is a five-minute task with an obvious requester, and closing one is an unowned task with no requester at all. Over a few years the arithmetic only ever runs one way.

Diagram showing a firewall rule base of around 1,900 rules narrowing through a filter of shadowed, duplicated, expired and any-any rules down to the much smaller set that actually carries traffic.A wide bar labelled 1,900 rules in the running config funnels down through a filter stage into a narrower bar labelled the rules actually carrying traffic. The caption notes that the gap between the two is the audit finding.1,900 rules in the running configshadowed · duplicated · expired · any-anythe rules actually carrying trafficThe gap between the two is the audit finding.

The gap between the config and the traffic is the finding.

The practical consequence is that the firewall stops being a statement of policy and becomes an archaeological record. That matters at audit time, but it matters more during an incident, when the question “could this have reached that?” needs an answer in minutes and the rule base cannot give one.

Scope and price

What you get, and what it costs

Configuration audit starts at ₹25,000. Beyond that the price is driven by scope, and we scope from a configuration export rather than a user count — a thousand users behind twelve simple rules is a smaller job than eighty users behind nine hundred.

What drives the price Why it matters What we ask for
Enforcement points Each firewall pair is a separate rule base with its own history, even when the policy is meant to be identical. How many pairs, and are they meant to match
Rule-base size Review effort tracks rule count and object nesting far more closely than it tracks user count or bandwidth. A sanitised config export
Log availability Hit counts separate a live rule from a dead one. Without logs the audit can still find shadowing and permissiveness, but not disuse. A representative log sample
Remediation Documenting a fix and carrying it out are different jobs. We quote them separately so the report stays independent. Whether you want the changes made

Scroll the table sideways on a narrow screen.

We do not quote a firewall audit from a user count alone. Send a config export and the number stops being a guess.

After the report

Where an audit usually leads

An audit is a diagnostic, and diagnostics are only worth commissioning if you are prepared to act on the result. In practice the findings point at one of four pieces of work.

NEXT

Rule-base remediation

Removing what is dead and tightening what is over-broad, in change windows, with a rollback position at every step.

NEXT

Platform migration

Sometimes the rule base is not salvageable and a clean rebuild on new hardware is cheaper than the cleanup. See firewall migration services.

NEXT

Ongoing management

Rule bases decay because nobody owns retirement. A managed service that owns it is the only durable fix. See firewall services.

NEXT

Maintenance cover

If the finding is stale firmware and untested failover, that is an AMC question rather than a rule question.

Questions

Firewall audit, answered

What is a firewall audit?

A structured review of what your firewall is actually configured to do, as opposed to what everyone believes it does. It covers the rule base, the objects and groups behind it, administrative access, logging, high-availability state and firmware. The output is a ranked list of findings with the change needed for each, not a tool dump.

How is this different from a VAPT or penetration test?

A penetration test attacks the outside of the estate and tells you what an attacker can reach. An audit reads the configuration from the inside and tells you why. They answer different questions and the findings rarely overlap. Most estates need both, and the audit is usually the cheaper one to act on. See our VAPT services.

How long does a firewall audit take?

For a single pair of firewalls with a few hundred rules, the review is typically a few days once we have the configuration and a log sample. Large multi-site estates take longer, and the variable is almost never the reading — it is how long it takes to find someone who can explain why a given rule exists.

Do you need access to our firewalls?

No. A sanitised configuration export and a representative log sample are enough for the review itself. Read-only access helps us confirm live state such as session counts and HA sync, but it is optional and we are equally happy working from exports under NDA.

What does a firewall audit cost?

Configuration audit starts at ₹25,000. The real drivers are the number of enforcement points, the size of the rule base and whether you need the remediation carried out as well as documented. We scope from a config export rather than a user count, because a user count tells us nothing about rule-base complexity.

Will you also fix what you find?

Yes, as a separate piece of work, and deliberately so. The audit has to be able to say uncomfortable things, which is easier when it is not a sales document for the remediation. If you want the fixes carried out we quote them separately and you are free to hand the report to anyone else.

Which firewall platforms do you audit?

FortiGate, Cisco ASA and Firepower, Palo Alto, Check Point, Sophos and SonicWall. We are a Fortinet partner with NSE-certified engineers, so FortiGate estates get the deepest review, but the audit method is vendor-neutral and the report is written to be readable by whoever runs the box next.

Next step

Get your rule base read by someone who did not write it

Send a sanitised configuration export and we will tell you what the audit would cover and what it would cost. If the rule base turns out to be in good order we will say so.