Firewall Review

Firewall Review: most firewalls keep passing traffic. That is not the same as still doing their job.

A FortiGate is deployed. Rules are configured. VPN is established. Firmware is current at the time. The environment works. Then time passes, and the firewall drifts quietly, rule by rule, exception by exception, firmware cycle by firmware cycle, until something external forces the question.

Inlight IT reviews FortiGate environments before the next policy change, hardware refresh or insurance review brings the firewall into question. Fortinet-experienced engineers examine where the firewall is exposed today, what needs to change first, and whether the existing appliance can be hardened before any replacement is considered.

What the review examines
Rule base and NAT
Stale rules, NAT exposure and open inbound paths
SSL inspection
What is decrypted, what is not, and why
Firmware and CVEs
FortiOS position and known CVE exposure
VPN, admin and Fabric
Remote access, privileged paths and Security Fabric
The drift problem

The situations that make a firewall review overdue

Firewalls do not fail loudly. They drift quietly, rule by rule, exception by exception, firmware cycle by firmware cycle, until something external forces the question. A cyber insurer asks for evidence the environment cannot produce. Essential Eight surfaces a control gap. A renewal quote arrives before anyone knows what should be replaced. An incident reveals an open path no one was watching.

The need for review usually shows up before the firewall fails outright. The situations below are where organisations most often start this conversation.

Nothing announces a problem. The firewall is still passing traffic. The exposure surfaces when a cyber insurance questionnaire, an Essential Eight assessment or an incident asks questions the environment cannot answer.

01Rules have accumulated for years without a clean-upRules added for projects that ended, servers that no longer exist, engineers who have moved on.Exceptions that became permanent. Nobody is confident removing them because nobody is certain what they were for. The rule base grows in one direction only, and every unreviewed rule is a path someone once opened and no one has closed.
02SSL inspection is off and the encrypted blind spot is wideningHTTPS is the primary delivery channel for modern malware, and most traffic is now encrypted.SSL inspection was either never enabled, or was attempted once and disabled when it disrupted users. The firewall keeps inspecting what it can see. Most of what matters is moving through traffic it cannot.
03FortiOS firmware is one or two cycles behindFirmware has fallen behind for sensible operational reasons.A patch broke something once, the maintenance window is awkward, no one owns the cadence. Known CVEs accumulate on the perimeter device itself, where they are most exposed and hardest to defend.
04Legacy VPN and contractor access has outlived its usefulnessUser VPN accounts for people who left months ago, vendor access scoped broadly because it was easier.Split-tunnel configurations nobody documented. The VPN works. That is not the same as the VPN being controlled.
05Branch firewall policy has drifted from head officeSome sites carry stronger policy, some carry local exceptions, some run older equipment.Security posture is inconsistent across locations even when the same vendor is deployed everywhere. The environment looks standardised on paper and behaves differently site by site.
06Insurance or Essential Eight is asking questions the firewall cannot answerInsurers and assessors want evidence, and "we have a firewall" is not a defensible answer.Insurers want evidence of SSL inspection, log retention, administrator access controls, segmentation and patch cadence. Essential Eight raises segmentation, logging and perimeter requirements. The gap is not the firewall, it is the evidence the firewall can produce.
07A refresh quote has arrived before the environment is understoodA reseller has proposed a replacement appliance, and the numbers may even be right.But whether the existing FortiGate can be hardened, whether the sizing is correct for actual SSL inspection load, and whether the new appliance operating model will be any stronger, none of that has been established yet.
When it fits

When a Firewall Review is the right next step

Deployment installs hardware. Management is everything that comes after: continuous rule hygiene, SSL inspection tuning, IPS profile tuning, firmware cadence, FortiGuard service planning, VPN access review, log triage and change governance. Most firewalls have been deployed. Far fewer are being managed. The review establishes the gap between the two states for the specific environment, and where the existing FortiGate can be hardened, it shows what needs to change first.

Firewall rules have accumulated over years without a structured clean-up
SSL inspection is off, partially enabled or not understood across the environment
FortiOS firmware is one or more cycles behind current releases
VPN access for contractors, vendors or former staff has not been reviewed recently
Branch or site firewall policy has drifted away from head office standards
A cyber insurance renewal is asking specific questions about posture, inspection and logging
An Essential Eight assessment is raising segmentation, logging or perimeter requirements
A hardware refresh has been proposed before the environment has been reviewed
Administrator access, MFA on management interfaces or privileged paths have not been audited
FortiGuard subscriptions are approaching renewal or have lapsed
The current FortiGate is being considered for SD-WAN, ZTNA or Security Fabric extension
One or more of these true? Book a Firewall Review
Deployment is not management

The hardware is usually right, the management is what has gone missing

Much of the risk in firewall environments is not a missing feature; it is an operating model gap. Deployment installs hardware; management is everything that comes after. The platform is capable of running better. The discipline around it has not been built.

A firewall that was installed
A firewall that is operated
Configured once, then left running. Rules accumulate for years and nobody owns the clean-up.
Rules audited and tightened on a rhythm, with stale entries identified and retired.
Firmware slips behind the cadence while known CVEs accumulate on the perimeter device.
Firmware governed to a defined cadence, with staged deployment and rollback planning.
SSL inspection is off, or was tried once and disabled when it disrupted users.
SSL inspection tuned and staged into production, risk-based, with defined exclusions.
IPS alerts pile up and go unread. Logs exist, but nobody owns them.
Logs, alerts and Security Fabric owned, triaged and turned into signal.
VPN and admin access are never re-checked. Contractor tunnels outlive the contractors.
VPN, contractor and admin access reviewed, named, time-bound and MFA-aligned.
Track record

Firewall management, evidenced

Multi-site
Users on a managed multi-site FortiGate environment
7
Operating surfaces examined, from rule base to Security Fabric
Read-only
The review runs without taking the firewall offline
Review-first
Hardening established with evidence before replacement
Fortinet
Engineers who operate FortiGate environments every day
What it covers

Inside the Firewall Review

Seven operating surfaces where exposure usually concentrates, in one view. The output is a prioritised list of what needs to change first, not a generic firewall report, and no hardware recommendation is made before the environment is understood.

01
Rule base and NAT exposure

The first place drift accumulates, and the last place it gets cleaned up. Firewall rules, NAT entries, source and destination scope, service scope, naming conventions and stale rule identification. Inbound exposure review, port forwarding validation, public service ownership and unnecessary external access. The aim is not cosmetic cleanup; it is to identify open paths nobody is watching.

02
SSL inspection posture

The encrypted traffic blind spot is now most of the traffic. What is being inspected, what is not, what is excluded and why. Certificate handling, application compatibility, staged rollout planning and privacy considerations. Leaving encrypted traffic entirely uninspected is a major visibility gap; broad inspection without planning disrupts users. The right model is staged and risk-based.

03
FortiOS firmware and CVE exposure

Known vulnerabilities on the device that controls the edge. Current firmware position, PSIRT awareness, known CVE exposure at the version in use, version selection logic, staged deployment approach and rollback planning. Firmware should be governed against a cadence, not patched only when something forces it.

04
VPN and remote access

Most VPN environments grant more access than the business intends. User VPN, site-to-site VPN, contractor and vendor access, MFA alignment, split-tunnel posture and legacy remote access methods. Accounts for users who have left, vendor access scoped broadly because it was easier. ZTNA fit assessed where the VPN model no longer matches how the business operates.

05
IPS, application control and FortiGuard

Alert noise is how genuine threats get missed. IPS profile selection and tuning, application control posture, web filtering categories, false positive handling and FortiGuard subscription status. Default profiles generate noise that teams stop reading. Tuning is what turns alerts into signal.

06
Administrator access and Security Fabric

The most privileged path is usually the least reviewed. Administrator access, MFA on management interfaces, role-based access, FortiManager and FortiAnalyzer coordination where applicable, log forwarding, retention and escalation ownership. Security Fabric value depends on whether it is being operated, not whether it is enabled.

07
Backup, change control and documentation

The firewall configuration is operating documentation, not a static artefact. Configuration backup, restore validation, known-good state documentation, change request review, technical validation, rollback planning, implementation record and post-change checks. The work that makes the next review easier and the next change safer.

Outcome paths

Review before replacement, not the other way around

Most firewall environments do not need to be replaced. They need to be reviewed, cleaned up and properly operated. Some genuinely do need replacement, but that decision should follow the review, not precede it.

The first step is still review. Replacement is sometimes the answer, it is rarely the starting point.
In these environments, replacement without review is solving the wrong problem. The review establishes which path applies.
Platform fit

FortiGate is capable. It is not automatically the answer.

FortiGate is one of the most capable firewall platforms available at its price point, and Inlight IT works extensively with Fortinet. Firewall, VPN, SD-WAN, IPS, web filtering, application control, SSL inspection and a ZTNA foundation run in the same FortiOS. The review still starts from the environment, not the product.

FortiGate fits when
Branch security, WAN performance and remote access need solving together
One FortiOS for firewall, VPN, SD-WAN, IPS and ZTNA is an advantage
The organisation can operate the platform properly, not just own it
Consider a different approach when
The environment needs cloud-native firewalling rather than an appliance
Access is better solved through ZTNA or SASE than traditional VPN
Internal segmentation needs a broader network redesign first
The real gap is operational ownership, not the firewall product

The review identifies the right next step based on the environment, not a product assumption. That may be hardening the existing FortiGate. It may be upgrading the appliance. It may be redesigning VPN access. It may be moving some access patterns toward ZTNA. It may be improving the operating model without changing any hardware.

A platform fits when the organisation can operate it properly, not when the data sheet looks complete.
How we run it

The review matters, what happens after it matters more

A Firewall Review is not a one-off audit document. It is the starting point of a more disciplined firewall operating model. The sequence below is how the engagement moves from review to ongoing management.

01

Review current exposure

Rules, NAT, VPN, administrator access, FortiOS firmware, FortiGuard services, SSL inspection, IPS, application control, web filtering, logging, backup and change control. The aim is to identify where the firewall is exposed today, before any hardware or policy change is committed to.

02

Map business dependencies

Users, sites, applications, VPNs, exposed services, integrations and operational dependencies mapped against the existing configuration. Firewall changes can break applications, VPNs, Microsoft 365 paths and site connectivity; mapping first means remediation does not become disruption.

03

Prioritise remediation

Externally exposed services, known CVEs, weak administrator access, stale VPN accounts, unsupported firmware, broad inbound rules and missing logging usually require earlier action than cosmetic cleanup. The output distinguishes urgent exposure from hygiene improvement.

04

Harden and tune

Stale rule removal, scope tightening, open service reduction, VPN access improvement, SSL inspection staged into production, IPS profile tuning, firmware updates, logging improvements, administrator access strengthening, FortiGuard alignment and backup validation.

Establish ongoing management: a clean firewall today does not stay clean on its own, the discipline is what holds.
Rules need review, firmware needs cadence, logs need ownership, changes need documentation, alerts need triage, subscriptions need renewal planning, VPN access needs review. The firewall needs to stay managed after the review work is complete.
Why Inlight IT

Firewall management treated as an operating discipline, not a product configuration

Firewall risk is rarely a missing feature. It is usually an operating model gap. Inlight IT approaches firewall work as the discipline around the appliance, not the appliance itself. What that means in practice:

01

Fortinet-experienced engineers

The review is performed by engineers who operate FortiGate environments daily. Rule hygiene, SSL inspection posture, FortiOS lifecycle, IPS tuning and FortiGuard planning are not concepts being applied for the first time on your environment.

02

Review before replacement

The default starting position is that the existing appliance can probably be hardened. Replacement is sometimes right, but rarely first. The review establishes which path applies for the specific environment.

03

An operating model, not a one-off audit

A Firewall Review is the starting point of an ongoing management discipline. Rule hygiene, firmware cadence, log ownership, change governance and VPN access review continue after the review is complete.

04

Security and networking together

Firewall policy connects to SD-WAN, branch connectivity, Microsoft 365 paths, VPN, ZTNA and future SASE design. The firewall is reviewed as part of the network and security model, not as an isolated device.

05

Continuous ownership after the work

A FortiGate reviewed once and then left to drift accumulates the same issues the review just resolved. The review only holds its value if the operating discipline continues after the work is done.

Common questions

Questions that come up before a Firewall Review

What happens in a Firewall Review scoping conversation?

A scoped review of the current FortiGate environment: rule base, NAT, VPN, administrator access, firmware posture, FortiGuard service status, SSL inspection, IPS, application control, web filtering, logging, backup configuration, Security Fabric coordination and change control. The output is a prioritised view of what needs to change first and whether the existing appliance can be hardened or needs replacement. It is not a sales presentation for new hardware.

What is the difference between a deployed FortiGate and a managed FortiGate?

A deployed FortiGate is configured once and left running. A managed FortiGate is continuously maintained: rules audited and tightened, firmware updated on a defined cadence, SSL inspection tuned, IPS profiles reviewed, VPN access controlled and policy adjusted as the network and threat landscape change. Misconfiguration drift is how most firewall environments accumulate exposure over time. Management is what closes that gap.

Does my firewall actually need SSL inspection?

Not every traffic flow should be decrypted, but some SSL inspection is usually required if the organisation wants meaningful visibility into encrypted web traffic. HTTPS is now the primary delivery channel for modern malware. Leaving encrypted traffic entirely uninspected creates a major visibility gap; turning on broad inspection without planning disrupts users and applications. The right model is staged, risk-based, with defined exclusions and proper certificate handling.

What happens if a FortiGuard subscription lapses?

The firewall continues to pass traffic, but the security services that depend on current threat intelligence start to degrade. IPS, antivirus, web filtering and DNS security stop receiving updates. Connectivity still works, security posture weakens over time. Renewal planning should happen before expiry, not after alerts start appearing.

Can Inlight IT manage a FortiGate deployed by another provider?

Yes. The environment can be reviewed and brought into a managed operating model regardless of who originally deployed it. The first step is understanding the current configuration, access model, firmware posture, licensing, logging, VPN setup, rule base and business dependencies. From there, what needs to be cleaned up, hardened, documented and managed going forward becomes clearer.

Does a Firewall Review require any disruption to live operations?

Generally no. The review itself is read-only, examining configuration, posture, logs and policy. Remediation work that follows the review is sequenced against business hours, application dependencies and rollback planning, and changes that affect traffic flow or inspection are tested and staged. The review does not require taking the firewall offline.

When is FortiGate the wrong platform?

Where the environment requires a cloud-native firewall architecture rather than an appliance-led model, where application access is better solved through ZTNA or SASE than traditional VPN, where internal segmentation requires broader network redesign before firewall replacement, or where the actual problem is operational ownership rather than the platform itself. The review identifies the right next step based on the environment, not a product assumption.

Does this work alongside our internal IT team?

Yes. The review and ongoing management can sit alongside an internal IT team or an existing MSP. Inlight IT provides Fortinet engineering depth, review discipline, firmware governance and ongoing operating ownership where the internal team does not have the scale or specialisation to maintain it. The internal team retains business context and day-to-day responsibility.

Practical next step

Review the firewall before the next hardware refresh, renewal or policy change

Book a Firewall Review