Firewall Auditing, Compliance, and Product Updates Blog
Practical firewall audit guides, FortiGate security notes, compliance-focused articles, and product updates intended for engineers and security reviewers.
Browse firewall audit guides by topic:
Guides
Latest firewall audit guides and updates

Run Critical FortiGate PSIRT Checks for Free with ConfigSentry
Use ConfigSentry's free PSIRT template to check an authorised FortiGate configuration against the critical Fortinet advisories currently included in the template.

ConfigSentry Product Update: More Ways to Audit, Monitor, and Report
A concise overview of recent ConfigSentry improvements, including expanded audit workflows, clearer reporting, recurring monitoring, and the current free trial.

FortiGate Firewall Audit Checklist: What Security Teams Should Review First
A practical checklist for reviewing FortiGate firewall configurations, reducing hidden exposure, and turning manual review work into repeatable evidence.

Firewall Rule Cleanup Best Practices for Reducing Risk and Complexity
How duplicate, stale, shadowed, and overly permissive firewall rules increase risk, and how structured review helps keep a rulebase defensible.

Why Any-Any Firewall Rules Are Still One of the Biggest Policy Risks
A plain-English explanation of why source any, destination any, service any rules are dangerous and how teams should approach remediation.

Firewall Compliance Audit Readiness: Turning Configuration Review into Evidence
How firewall configuration reviews support standards-aligned evidence for PCI DSS, ISO 27001, NIST, CIS, and internal security policies.

PCI Firewall Review: Practical Questions to Ask Before an Assessor Does
A focused guide to reviewing firewall rules, segmentation, management access, and evidence before a PCI-focused security review.

Network Segmentation and Firewall Policy
Why segmentation is only effective when firewall rules, objects, interfaces, and routing assumptions are reviewed as the environment changes.

Firewall Rule Order Matters: How Policy Placement Can Change Security Outcomes
Why the same firewall rules can behave differently depending on order, shadowing, and overlapping policy logic.

Firewall Monitoring and Configuration Drift: Why One-Off Reviews Are Not Enough
How recurring firewall audits help detect drift after emergency changes, migrations, and routine operational work.

FortiGate Hardening: Common Misconfigurations
A practical overview of FortiGate hardening areas such as admin access, services, logging, VPN exposure, and management-plane hygiene.

Firewall Security Standards Mapping: Useful Guidance, Not a Magic Compliance Badge
How standards mappings help security teams interpret firewall findings without pretending that automated checks alone certify compliance.

Executive vs Engineer Firewall Reports: Why Both Views Matter
Why firewall audit output should support technical remediation and management-level risk conversations without mixing the two audiences together.

The Firewall Rule Lifecycle: From Emergency Change to Forgotten Risk
How firewall rules are created, changed, inherited, forgotten, and eventually become risk unless teams review them regularly.

Firewall Audit Automation vs Manual Review: Where Each Fits
Why automation improves consistency and coverage, while engineer judgement remains essential for context, exceptions, and safe remediation.

ConfigSentry Update: Making the Product Easier to Understand
Chris Hansford shares the April 2026 work to make ConfigSentry clearer, easier to evaluate, and better connected to the audit experience.

Why I Created ConfigSentry
Founder Chris Hansford introduces ConfigSentry, explains the firewall-audit problems that led to it, and shares what he wants the product to achieve.