Firewall Policy Baseline: 10 Rules Every Indian Enterprise Must Configure

By Vikram Singh · 24 March 2026

Why Firewall Policy Governance Matters

A firewall is only as good as its ruleset. Enterprise firewalls accumulate rules over years — each added for a specific purpose, most never reviewed or removed. A 2024 FireMon study found that 40% of enterprise firewall rules are overly permissive and 29% are completely unused. These orphaned and overpermissive rules represent silent risk. ISO/IEC 27001:2022 Annex A.8.20 requires network controls including firewall management. CERT-In mandates access controls on all network boundaries. The RBI Cybersecurity Framework explicitly requires quarterly firewall rule reviews for BFSI organisations.

10 Firewall Baseline Rules — Every Enterprise Must Have These

#RuleWhy It Matters
1Implicit deny-all at bottom of every rulesetDefault deny is the foundation of any secure policy
2Block inbound traffic to RFC 1918 addresses from internetPrevents spoofed internal-source attacks
3Block all outbound traffic except explicitly allowed portsLimits C2 beacon traffic from compromised hosts
4Restrict management protocols (SSH/HTTPS) to mgmt VLANPrevents user-network access to device admin interfaces
5Log all denied traffic (source, destination, port, timestamp)CERT-In requires log retention ≥180 days
6Block Tor exit nodes and known malicious IP rangesReduces C2 communication risk using threat intel feeds
7Enable IPS on internet-facing and DMZ interfacesActive threat prevention, not just detection
8Anti-spoofing (uRPF) on all external interfacesBlocks IP spoofing attacks at perimeter
9Each rule must have owner, purpose, and review dateEnables quarterly rule review and orphan removal
10Separate internet-facing and inter-VLAN firewall policiesDifferent risk profiles require distinct policy approaches

The Quarterly Firewall Rule Review Process

Every firewall rule must be reviewed at least quarterly. The review process: export the full ruleset, identify rules with no hit counter activity in 90 days (candidates for removal), review any "any/any" or overly broad rules, confirm owner acknowledgement for all retained rules, and document the review with a sign-off. This review itself is an ISO 27001 evidence artefact.

SSL/TLS Inspection Considerations

Over 90% of enterprise traffic is now encrypted. A perimeter firewall that cannot inspect HTTPS traffic is effectively blind to the majority of inbound and outbound threats. NGFW platforms with SSL/TLS inspection capability (Palo Alto, Fortinet, Check Point) are increasingly required for CERT-In compliance evidence demonstrating effective perimeter control.

Firewall Policy Assessment On-Site

InfraVeritas 360 conducts on-site firewall policy reviews — checking rule set quality, logging configuration, inter-VLAN controls, and CERT-In compliance evidence — as part of every IGaaS assessment.

Review Your Firewall Policy →