Six Best Practices for Secure Network Firewall Configuration
- Configure Network Firewalls to Block Traffic by Default. ...
- Follow the Principle of Least Privilege. ...
- Specify Source IP Addresses Unless Everyone Needs Access. ...
- Designate Specific Destination Ports. ...
- Open the Firewall Ports That Users Expect.
What is a good firewall policy?
A good firewall policy also has a formal change procedure to manage change requests. It should block traffic by default, allow only specific traffic to identified services. It should set all explicit firewall rules first. There should be explicit drop rules (Cleanup Rules) at the bottom of each security zone.