top of page
background.jpg

​

Tufin Tuesday | Network Security Policy Management Series Issue #01 | Your Firewall Rule Gets Hits. But Is It Really Right?

Sep 28
2 min read

The fact that a firewall rule is actively used does not mean it is correctly designed.


Take this rule as an example:


  • Source: Application Network

  • Destination: Database Network

  • Service: Any

  • Action: Allow


The rule may receive traffic every day. At first glance, nothing appears wrong.


But examining actual traffic may reveal that the only communication is:


2 application servers → 1 database server → TCP/1433


The access permitted by the firewall is much broader than the actual requirement.

This is where an often overlooked risk in firewall rulebases begins.


Finding Unused Rules Is Not Enough


Firewall cleanup projects usually begin with familiar areas:


  • Rules that have not been used for a long time

  • Disabled rules

  • Duplicate rules

  • Shadowed rules


Cleaning these up is important. But there is an even more critical category:


Rules that are used but are broader than necessary.


These rules do not appear as problems in traditional unused-rule reports. There is traffic. There are hits. The rule is active.


Yet much of the permitted access may never actually be used.


What Does SecureTrack+ Reveal?


Tufin SecureTrack+ can analyze firewall policies alongside actual usage data, rather than treating them only as configurations.


The question moves beyond "Is this rule being used?" It becomes:


"How much of this rule's source, destination and service scope is actually used?"


For example, the current policy may be:


10.10.0.0/16 → 10.20.0.0/16 → Any


While actual traffic is limited to:


10.10.5.21 → 10.20.8.15 → TCP/443


The gap directly represents unnecessary access exposure.


The SecureTrack+ Rule Optimizer approach can identify these rules and provide analysis to support narrower, more controlled policy design.


Your firewall rule gets hits, but is it really right? Tufin SecureTrack+ rule optimization – Zero Second

Another Challenge: Shadowed Rules


Imagine the following two firewall rules:


  • Rule 10: Corporate Network → DB Network → HTTPS → Allow

  • Rule 30: Finance Network → DB Network → HTTPS → Deny


If the first rule covers the second, the security team may believe access from the Finance Network is blocked. In reality, Rule 10 has already allowed the traffic.


A Deny rule exists in the configuration. But the expected security control is not being enforced.


Shadowed-rule analysis is therefore more than rulebase cleanup. It helps answer:


"Is the security policy we defined actually being enforced?"


The Real Goal Is Not Just Fewer Rules


The success of a firewall optimization project should not be measured solely by saying "We reduced 5,000 rules to 3,000."


The real goal is:


A rulebase that permits no more access than the business actually needs.


SecureTrack+ enables centralized analysis of:


  • Unused rules

  • Shadowed policies

  • Overly broad access

  • Unused objects

  • Policy violations


Sometimes, the most important findings are not rules that can be deleted.


They are actively used rules that allow far more access than they should.


What Does Your Rulebase Look Like?


Your firewall rulebase may contain thousands of rules. Do you know how many are truly necessary?


More importantly:


How many of your active rules allow more access than actual traffic requires?


Together, we can analyze your current firewall policies with Tufin SecureTrack+ and uncover hidden risks in your rulebase.


Zero Second | Tufin – Network Security Policy Management.

Tufin Network Security Policy Management Series #01, prepared by Zero Second.

Comments


bottom of page