Why Firewall Policy Governance Matters
A firewall is only as good as its ruleset. Enterprise firewalls accumulate rules over years — each added for a specific purpose, most never reviewed or removed. A 2024 FireMon study found that 40% of enterprise firewall rules are overly permissive and 29% are completely unused. These orphaned and overpermissive rules represent silent risk. ISO/IEC 27001:2022 Annex A.8.20 requires network controls including firewall management. CERT-In mandates access controls on all network boundaries. The RBI Cybersecurity Framework explicitly requires quarterly firewall rule reviews for BFSI organisations.
10 Firewall Baseline Rules — Every Enterprise Must Have These
| # | Rule | Why It Matters |
|---|---|---|
| 1 | Implicit deny-all at bottom of every ruleset | Default deny is the foundation of any secure policy |
| 2 | Block inbound traffic to RFC 1918 addresses from internet | Prevents spoofed internal-source attacks |
| 3 | Block all outbound traffic except explicitly allowed ports | Limits C2 beacon traffic from compromised hosts |
| 4 | Restrict management protocols (SSH/HTTPS) to mgmt VLAN | Prevents user-network access to device admin interfaces |
| 5 | Log all denied traffic (source, destination, port, timestamp) | CERT-In requires log retention ≥180 days |
| 6 | Block Tor exit nodes and known malicious IP ranges | Reduces C2 communication risk using threat intel feeds |
| 7 | Enable IPS on internet-facing and DMZ interfaces | Active threat prevention, not just detection |
| 8 | Anti-spoofing (uRPF) on all external interfaces | Blocks IP spoofing attacks at perimeter |
| 9 | Each rule must have owner, purpose, and review date | Enables quarterly rule review and orphan removal |
| 10 | Separate internet-facing and inter-VLAN firewall policies | Different risk profiles require distinct policy approaches |
The Quarterly Firewall Rule Review Process
Every firewall rule must be reviewed at least quarterly. The review process: export the full ruleset, identify rules with no hit counter activity in 90 days (candidates for removal), review any "any/any" or overly broad rules, confirm owner acknowledgement for all retained rules, and document the review with a sign-off. This review itself is an ISO 27001 evidence artefact.
SSL/TLS Inspection Considerations
Over 90% of enterprise traffic is now encrypted. A perimeter firewall that cannot inspect HTTPS traffic is effectively blind to the majority of inbound and outbound threats. NGFW platforms with SSL/TLS inspection capability (Palo Alto, Fortinet, Check Point) are increasingly required for CERT-In compliance evidence demonstrating effective perimeter control.
Firewall Policy Assessment On-Site
InfraVeritas 360 conducts on-site firewall policy reviews — checking rule set quality, logging configuration, inter-VLAN controls, and CERT-In compliance evidence — as part of every IGaaS assessment.
Review Your Firewall Policy →