As a system integrator, I constantly interact with new infrastructures and customers, which means I often come across a lot of “interesting things.” From time to time, I’m engaged in services to evaluate firewall configurations. What are the most common configuration or deployment mistakes I encounter? If you’re curious, read below:
1. Overly General Firewall Access Policies
The most common and significant mistake is having overly general firewall access policies. Firewalls should operate under the principle of “block by default, allow by design.” While this approach requires significant effort, it’s essential for robust security. Unfortunately, in my experience, only a small percentage of organizations manage their access policies effectively.
2. Using Default Security Profiles
I’ve never seen a firewall configured with best practices straight out of the box. Security profiles (antivirus, URL filtering, IPS, DNS, etc.) should be carefully tuned to meet specific needs and follow best practices. Default configurations often lack advanced protections, leaving systems vulnerable.
3. Lack of Regular Configuration Reviews
Technology evolves constantly, and firewall vendors frequently add new protection capabilities. However, these features often need to be manually enabled. On top of that, we’re all human—mistakes happen. For these reasons, firewall configurations should be reviewed regularly to ensure they remain effective.
4. Outdated Threat Signature Databases
It’s not uncommon to find firewalls with security features configured but not set to update threat signatures. In such cases, the security mechanisms are essentially useless. Unfortunately, I’ve seen this issue countless times.
5. Firewall Protections That Are Easy to Bypass
Some time ago, I wrote an article about how easily firewall protections can be bypassed. Sadly, I’ve encountered many organizations where such bypasses were possible due to poor hardening. Devices should be thoroughly secured to prevent these vulnerabilities.
6. Unencrypted Internet Traffic
Internet traffic often isn’t decrypted. While decryption requires significant effort and can disrupt some types of communication, it is a critical layer of security. Decryption policies should also be clearly defined in work regulations, as the effort goes beyond just IT staff.
In Summary
Even the best-of-breed solutions won’t provide much benefit if they’re poorly configured and maintained. An organization is only as secure as its security controls are properly configured. Take the time to review, tune, and update your firewall configurations—it’s worth the effort.