The Importance of Firewall Management
The corporate firewall is the first line of defense protecting the network from external threats; yet it is also one of the most frequently misconfigured components. Research shows that 80% of firewall rule sets in enterprise environments contain unnecessary or conflicting rules. This creates both security vulnerabilities and performance degradation.
Core Principles of Firewall Rule Design
Least Privilege
Every rule should permit only the necessary traffic, only between the necessary sources and destinations, and only for the necessary duration.
Default Deny
At the end of the rule set, there must be a rule that blocks everything that is not explicitly permitted:
Last Rule: ANY → ANY → ANY → DENY (log: yes)
Rule Ordering
Firewall rules are processed top-to-bottom and stop at the first match:
- Management access rules (SSH, HTTPS to the management interface)
- Trusted network traffic (LAN → Internet)
- DMZ rules
- Intranet services
- Specific restriction rules
- Default deny
FortiGate Rule Configuration
Creating a Policy (CLI)
config firewall policy
edit 100
set name "LAN_to_Internet_HTTP"
set srcintf "internal"
set dstintf "wan1"
set srcaddr "LAN_Subnet"
set dstaddr "all"
set action accept
set schedule "always"
set service "HTTP" "HTTPS"
set logtraffic all
set nat enable
set utm-status enable
set av-profile "default"
set webfilter-profile "kurumsal-filtre"
next
end
Address Objects
Rules should never be written with raw IP addresses; meaningful address objects must be used:
config firewall address
edit "Muhasebe_VLAN"
set subnet 192.168.10.0 255.255.255.0
next
edit "ERP_Sunucu"
set type ipmask
set subnet 192.168.1.50 255.255.255.255
next
end
Sophos Firewall Rule Management
Sophos Firewall (XG/SFOS) combines rule-based policies with business application logic:
Application Control Policy
Firewall Rules > Add Rule
Kaynak: İç ağ (LAN)
Hedef: WAN (İnternet)
Uygulama: Social Media (engelle)
Uygulama: Business SaaS (izin ver + loglama)
İçerik tarama: HTTPS denetimi (SSL inspection)
Zero-Day Threat Protection
Configuring sandboxing (Sandstorm) in Sophos Firewall:
Protect > Advanced Threat > Sandstorm
Dosya türleri: EXE, Office, PDF, ZIP
Eylem: Analiz beklenirken tut
Rule Cleanup and Optimization
Over time the rule set grows and becomes complex. Regular cleanup is essential:
Identifying Unused Rules
- FortiGate:
diagnose firewall iprope show; rules with a hit count of zero are listed. - Sophos: Check the "Last Used" column in the rule list; evaluate rules that have not been used for 90+ days.
Rule Set Review Checklist
- Conflicting rules: Does a more general rule render a more specific rule below it ineffective?
- Shadowed rules: Rules that can never be reached
- Redundant object duplication: The same IP defined under multiple objects
Change Management
Firewall rule changes must be subject to a change management process:
- Request: Written description, business justification, source/destination/port/protocol
- Review: Approval by the security team
- Test environment: Validation in a test environment where possible
- Implementation: Change window (outside business hours)
- Verification: Is the rule working? Are unintended connections being blocked?
- Documentation: Rule purpose, creation date, rule owner
To automatically log all rule changes in FortiGate, configure config log setting > set log-forward-override-setting enable.
Layered Security with ACLs
Applying ACLs (Access Control Lists) on Layer 3 switches and routers complements firewall rules:
# Cisco IOS ACL örneği — VLAN arası kısıtlama
ip access-list extended MUHASEBE_TO_ERP
permit tcp 192.168.10.0 0.0.0.255 host 192.168.1.50 eq 1433
deny ip 192.168.10.0 0.0.0.255 192.168.1.0 0.0.0.255
permit ip any any
Logging and Monitoring
Firewall logs are the primary data source for security operations:
- Blocked traffic: Should be logged by default (especially traffic blocked between internal networks)
- Permitted traffic: Access to sensitive servers should be logged
- Log management: Logs should be forwarded to a SIEM (Splunk, Microsoft Sentinel, Graylog)
- Retention: At least 90 days; 1 year for legal compliance
Conclusion
Firewall rule management is not a one-time configuration — it is an ongoing discipline. A clean rule set, proper object structure, change management, and regular audits improve both network security and performance. As NRC Sistem, we provide FortiGate and Sophos Firewall installation, policy design, rule auditing, and 24/7 firewall management services.