Cyber Security

Firewall Rule Management Guide: Configuring Enterprise Network Correctly

8 min read 1 August 2025

The Importance of Firewall Management

The corporate firewall is the first line of defense protecting the network from external threats; yet it is also one of the most frequently misconfigured components. Research shows that 80% of firewall rule sets in enterprise environments contain unnecessary or conflicting rules. This creates both security vulnerabilities and performance degradation.

Core Principles of Firewall Rule Design

Least Privilege

Every rule should permit only the necessary traffic, only between the necessary sources and destinations, and only for the necessary duration.

Default Deny

At the end of the rule set, there must be a rule that blocks everything that is not explicitly permitted:

Last Rule: ANY → ANY → ANY → DENY (log: yes)

Rule Ordering

Firewall rules are processed top-to-bottom and stop at the first match:

  1. Management access rules (SSH, HTTPS to the management interface)
  2. Trusted network traffic (LAN → Internet)
  3. DMZ rules
  4. Intranet services
  5. Specific restriction rules
  6. Default deny

FortiGate Rule Configuration

Creating a Policy (CLI)

config firewall policy
    edit 100
        set name "LAN_to_Internet_HTTP"
        set srcintf "internal"
        set dstintf "wan1"
        set srcaddr "LAN_Subnet"
        set dstaddr "all"
        set action accept
        set schedule "always"
        set service "HTTP" "HTTPS"
        set logtraffic all
        set nat enable
        set utm-status enable
        set av-profile "default"
        set webfilter-profile "kurumsal-filtre"
    next
end

Address Objects

Rules should never be written with raw IP addresses; meaningful address objects must be used:

config firewall address
    edit "Muhasebe_VLAN"
        set subnet 192.168.10.0 255.255.255.0
    next
    edit "ERP_Sunucu"
        set type ipmask
        set subnet 192.168.1.50 255.255.255.255
    next
end

Sophos Firewall Rule Management

Sophos Firewall (XG/SFOS) combines rule-based policies with business application logic:

Application Control Policy

Firewall Rules > Add Rule
Kaynak: İç ağ (LAN)
Hedef: WAN (İnternet)
Uygulama: Social Media (engelle)
Uygulama: Business SaaS (izin ver + loglama)
İçerik tarama: HTTPS denetimi (SSL inspection)

Zero-Day Threat Protection

Configuring sandboxing (Sandstorm) in Sophos Firewall:

Protect > Advanced Threat > Sandstorm
Dosya türleri: EXE, Office, PDF, ZIP
Eylem: Analiz beklenirken tut

Rule Cleanup and Optimization

Over time the rule set grows and becomes complex. Regular cleanup is essential:

Identifying Unused Rules

  • FortiGate: diagnose firewall iprope show; rules with a hit count of zero are listed.
  • Sophos: Check the "Last Used" column in the rule list; evaluate rules that have not been used for 90+ days.

Rule Set Review Checklist

  • Conflicting rules: Does a more general rule render a more specific rule below it ineffective?
  • Shadowed rules: Rules that can never be reached
  • Redundant object duplication: The same IP defined under multiple objects

Change Management

Firewall rule changes must be subject to a change management process:

  1. Request: Written description, business justification, source/destination/port/protocol
  2. Review: Approval by the security team
  3. Test environment: Validation in a test environment where possible
  4. Implementation: Change window (outside business hours)
  5. Verification: Is the rule working? Are unintended connections being blocked?
  6. Documentation: Rule purpose, creation date, rule owner

To automatically log all rule changes in FortiGate, configure config log setting > set log-forward-override-setting enable.

Layered Security with ACLs

Applying ACLs (Access Control Lists) on Layer 3 switches and routers complements firewall rules:

# Cisco IOS ACL örneği — VLAN arası kısıtlama
ip access-list extended MUHASEBE_TO_ERP
 permit tcp 192.168.10.0 0.0.0.255 host 192.168.1.50 eq 1433
 deny   ip 192.168.10.0 0.0.0.255 192.168.1.0 0.0.0.255
 permit ip any any

Logging and Monitoring

Firewall logs are the primary data source for security operations:

  • Blocked traffic: Should be logged by default (especially traffic blocked between internal networks)
  • Permitted traffic: Access to sensitive servers should be logged
  • Log management: Logs should be forwarded to a SIEM (Splunk, Microsoft Sentinel, Graylog)
  • Retention: At least 90 days; 1 year for legal compliance

Conclusion

Firewall rule management is not a one-time configuration — it is an ongoing discipline. A clean rule set, proper object structure, change management, and regular audits improve both network security and performance. As NRC Sistem, we provide FortiGate and Sophos Firewall installation, policy design, rule auditing, and 24/7 firewall management services.

All posts