Next-generation firewall policy review for [REDACTED] covering 4 Palo Alto PA-5220 firewalls protecting the core banking DMZ, internet edge, and inter-datacenter segments. Engagement ref. ENG-2025-0571.
Plaidnox reviewed 1,847 firewall rules across four Palo Alto PA-5220 firewalls for [REDACTED]. The review assessed rule quality, shadowed and unused rules, overly permissive policies, and zone-to-zone segmentation effectiveness.
The review identified 22 high-priority policy issues including 8 any-any permit rules on the internet edge, 312 unused rules (not matched in 180 days), 47 rules permitting clear-text protocols (HTTP, Telnet, FTP) into financial system zones, and inadequate micro-segmentation between the card processing and general banking segments.
| Firewall | Rules | Unused | Any-Any | Risk |
|---|---|---|---|---|
| FW-EDGE-01 (Internet) | 412 | 84 | 3 | Critical |
| FW-DMZ-01 (DMZ) | 568 | 102 | 2 | High |
| FW-DC-01 (DC East) | 441 | 74 | 2 | Medium |
| FW-DC-02 (DC West) | 426 | 52 | 1 | Medium |
| ID | Finding | Priority |
|---|---|---|
| FW-001 | 3 any-any permit rules on FW-EDGE-01 . allow all inbound and outbound traffic without inspection | Critical |
| FW-002 | Card processing zone reachable from general banking zone without application-level controls | Critical |
| FW-003 | 47 rules allow HTTP (port 80) into financial system zones . should require HTTPS minimum | High |
| FW-004 | Telnet permitted from network management zone to 28 network devices . should be SSH only | High |
| FW-005 | 312 unused rules create management overhead and ambiguity . should be decommissioned | Medium |
| Action | Timeline | Owner |
|---|---|---|
| Remove and replace all 8 any-any permit rules with explicit application-aware policies | Wk 1-2 | Network Ops |
| Implement micro-segmentation between card processing and banking zones (PCI DSS Req 1.3) | Wk 2-6 | Plaidnox / Network |
| Block HTTP, Telnet, FTP on all rules targeting financial system zones | Wk 1-3 | Network Ops |
| Decommission 312 unused rules following change control process | Wk 3-8 | Network Ops |
| Enable URL filtering and App-ID inspection on internet edge | Wk 4-6 | Plaidnox / Network |