Your firewall is the one piece of equipment in the building that works every day and gets attention roughly never. Somebody installed it, everything worked, and the box went into a closet where it has been humming ever since. That is a compliment to how well modern firewalls run. It is also the problem.

A firewall is closer to a company vehicle than a smoke detector. It needs scheduled service, and skipping that service causes no immediate breakdown, which is exactly why it keeps getting skipped. Here is what an annual firewall checkup looks like, in plain terms, and why each item is on the list.

Firmware, and Why Edge Devices Get Attention

Firewalls, routers, and remote access appliances sit at the boundary between your network and the internet. Security people call these edge devices, because they live at the edge of everything you own. They are reachable from outside by design, which is what makes them useful and also what makes them interesting to attackers.

This is not our opinion. In joint guidance on edge devices published in 2025 with international partners, CISA and NSA state that malicious actors are increasingly targeting internet facing edge devices to gain unauthorized access to networks. That guidance recommends organizations ensure prompt application of patches and updates to edge devices to protect against known vulnerabilities. NIST said the same thing years earlier in Special Publication 800-41 Revision 1, published in 2009, which states plainly that firewall software should be patched as vendors provide updates to address vulnerabilities.

The practical takeaway is simple. Firmware is the software running inside the firewall itself, and it needs updates the same way a computer does. Find out how yours gets updated, whether that happens automatically, and who confirms it worked. Also find out the manufacturer’s end of support date for your model. The same joint guidance advises identifying devices that have reached end of life and removing or replacing them, and a firewall the manufacturer no longer patches cannot be secured by any amount of careful configuration.

The Rules Somebody Added Three Years Ago

Every firewall holds a list of rules describing what traffic is allowed. Over time that list grows. A vendor needed access for an installation. A former employee needed to reach a machine from home. A copier project required a port opened “temporarily.” Each rule was reasonable on the day it was written. Nobody ever went back.

NIST addresses this directly in SP 800-41 Revision 1, published in 2009, recommending that firewall rulesets and policies be managed through a formal change management process, with ruleset reviews or tests performed periodically to confirm continued compliance with the organization’s policies. The same document says firewall policy should be maintained and updated as new classes of attacks arise or as the organization’s needs regarding network applications change.

A rule review does not require deep technical skill to start. Print the rule list and go line by line with these questions.

  • What is this for? If nobody in the room can answer, that is the finding.
  • Who asked for it, and are they still here? Rules tied to departed staff or finished projects are the easiest wins.
  • Is it as narrow as it could be? A rule that allows one specific address is better than one that allows the entire internet.
  • Does it have an end date? Temporary access should be written down with an expiration, then actually removed.

NIST’s underlying principle is worth stating outright: generally, all inbound and outbound traffic not expressly permitted by the firewall policy should be blocked, because that traffic is not needed by the organization. Start from “no” and add exceptions deliberately.

What Is Actually Open to the Internet

There is a difference between what you think is exposed and what is exposed. Ports are numbered doors into your network, and over the years a surprising number get propped open by remote access tools, cameras, building systems, phone systems, and software installers that quietly requested a path in.

The 2025 joint edge device guidance from CISA, NSA, and their international partners recommends regularly auditing and disabling unused features and ports to minimize the attack surface. That is the whole job. Get a current list of everything reachable from outside, match each entry to a business reason, and close what does not have one. Pay particular attention to remote desktop access and to management interfaces for the firewall itself, which rarely need to be reachable from the open internet at all.

Licenses, Logs, and the Default Password

Three quieter failures round out the checkup, and all three are common.

  • Expired subscriptions. Most business firewalls sell the hardware once and the protection by subscription. Web filtering, intrusion prevention, and threat feeds usually depend on an active license. When that license lapses, the device typically keeps passing traffic while the filtering silently stops. Everything looks fine. Know your renewal dates and confirm the features are actually active, not just purchased.
  • Logs nobody reads. NIST SP 800-41 Revision 1, published in 2009, recommends that logs and alerts be continuously monitored to identify threats, both successful and unsuccessful. The 2025 joint edge device guidance similarly calls for centralized visibility and log access to detect and investigate security incidents, and for those event logs to be backed up. A firewall logging to a small local buffer that overwrites itself every few days gives you nothing to look at after an incident.
  • Default credentials. A CISA Secure by Design alert published in 2023 states that studies by CISA show the use of default credentials is a top weakness threat actors exploit to gain access to systems, and that malicious cyber actors continue to exploit default passwords on internet exposed systems. Confirm that the factory administrator account has been changed or disabled, that every administrator has an individual login, and that multi-factor authentication is enabled on firewall administration wherever the device supports it.

The Annual Checkup, Start to Finish

  1. Confirm the model is still supported by the manufacturer, with a known end of support date on your calendar.
  2. Apply current firmware during a planned window, and verify the version afterward.
  3. Review every rule and remove what no longer has an owner or a purpose.
  4. Inventory what is exposed to the internet and close anything without a business reason.
  5. Check license and subscription status for every protection feature you believe you are paying for.
  6. Send logs somewhere durable and decide who looks at them and how often.
  7. Audit administrator accounts, remove defaults and departed staff, and turn on multi-factor authentication.
  8. Save a configuration backup offline so a failed device can be replaced in hours instead of days.

The Bottom Line

None of this is dramatic, and none of it needs to be. A firewall checkup is maintenance, like changing the oil. Put it on the calendar once a year, work the list, write down what you found, and move on. The businesses that get burned are almost never the ones that made a bold mistake. They are the ones where nothing was wrong on the day it was installed and nobody looked again for six years.

Remember too that the firewall protects the connection, not the data itself. Outages, provider problems, and cloud service interruptions are separate risks with separate plans, which we walked through in what a cloud outage means for your business. The firewall checkup is one line in a broader security routine, and we covered the rest in why cybersecurity is no longer optional.

Harrison Ward Technology reviews and maintains firewalls for small and mid-sized businesses across Denton County, including firmware, rule cleanup, license status, and logging. If you are not sure when yours was last touched, that is a good reason to ask. Contact us today.


Sources:

Comments are closed

This website uses cookies and asks your personal data to enhance your browsing experience. We are committed to protecting your privacy and ensuring your data is handled in compliance with the General Data Protection Regulation (GDPR).