Firewall Configuration Best Practices: Building Your Digital Perimeter

Firewall Configuration Best Practices

Proper firewall configuration is the foundation of network security for South African businesses. With local organisations facing an average of 1,450 cyberattacks per week—a 4% year-on-year increase—your firewall is often the first and last line of defence. Yet many businesses treat firewall setup as a "set and forget" exercise, leaving dangerous gaps that attackers eagerly exploit.

In 2024, network-edge devices became prime targets for cybercriminals. According to IBM's Cost of a Data Breach Report, the average breach costs South African organisations R53.1 million. With 69% of local businesses hit by ransomware according to Sophos, getting your firewall configuration right isn't optional—it's critical for survival.


Why Firewall Configuration Matters More Than Ever

South Africa sits at the centre of Africa's cybersecurity storm. ESET's 2024 Threat Report reveals that over 40% of ransomware attacks and 35% of infostealer incidents detected on the continent targeted South African organisations. INTERPOL recorded 17,849 ransomware detections in South Africa in 2024—the highest in Africa.

Despite these threats, many SMBs remain dangerously exposed:

Reality CheckStatistic
SA organisations attacked weekly1,450 times
SMBs targeted by cyberattacks43%
SMBs adequately preparedOnly 14%
Commercial entities with cyber insurance26%
Average breach cost (SA)R53.1 million

Your firewall stands between your business and these threats. But a misconfigured firewall provides a false sense of security—like a locked door with the key left in the lock. Proper firewall configuration ensures your perimeter actually protects you.


Understanding Modern Firewall Capabilities

Today's next-generation firewalls (NGFWs) go far beyond simple port and protocol filtering. Before diving into configuration best practices, understand what your firewall can do:

Core NGFW Features

FeatureFunctionWhy It Matters
Stateful Packet InspectionTracks connection states, not just individual packetsBlocks malformed or out-of-sequence traffic
Deep Packet Inspection (DPI)Examines packet contents, not just headersDetects malware and exploits hidden in legitimate traffic
Application AwarenessIdentifies applications regardless of portBlocks unauthorized apps even on standard ports
Intrusion Prevention (IPS)Detects and blocks known attack patternsStops exploits before they reach targets
SSL/TLS InspectionDecrypts and inspects encrypted trafficReveals threats hiding in HTTPS connections
Threat IntelligenceReal-time updates on malicious IPs/domainsBlocks known bad actors automatically
User Identity IntegrationLinks traffic to specific usersEnables user-based policies and auditing

If your firewall lacks these capabilities, it's time to upgrade. Legacy firewalls that only filter by port and IP address cannot protect against modern threats. Investing in proper firewall configuration starts with having the right hardware.


The Golden Rules of Firewall Configuration

These fundamental principles should guide every firewall configuration decision. Violate them at your peril.

Rule 1: Default Deny — Block Everything First

The most critical principle: deny all traffic by default and permit only by exception.

Many administrators make the mistake of starting with permissive rules and trying to block bad traffic. This approach fails because you cannot anticipate every threat. Instead:

  • Start with a rule that blocks all inbound AND outbound traffic
  • Add specific allow rules only for traffic you explicitly require
  • Document the business justification for every allow rule
  • Review and remove rules that are no longer needed
# Conceptual firewall rule order
1. Allow established/related connections (stateful)
2. Allow specific required services (explicit permits)
3. Deny and log everything else (default deny)

This ensures nothing passes through without explicit authorisation. If you cannot explain why a rule exists, it probably shouldn't.

Rule 2: Control Outbound Traffic — Not Just Inbound

Most organisations focus exclusively on inbound threats while ignoring outbound traffic. This is a critical mistake. Consider what outbound access enables:

  • Malware communication: Ransomware and trojans need to contact command-and-control servers
  • Data exfiltration: Stolen data must leave your network somehow
  • Lateral movement tools: Attackers download additional tools after initial compromise

Effective firewall configuration restricts outbound traffic to necessary destinations and ports:

Outbound RuleRecommendation
Web browsing (HTTP/HTTPS)Allow through web proxy with logging and filtering
DNSAllow only to approved internal or external DNS servers
EmailAllow only from mail servers to specified relays
Direct internet from serversBlock — route through proxies
Cloud servicesAllow specific services by IP/domain where possible
Everything elseDeny by default

When malware cannot phone home, it cannot receive instructions or exfiltrate data. Outbound controls dramatically limit the damage from successful intrusions.

Rule 3: Segment Your Network — Contain the Blast Radius

Network segmentation limits lateral movement. When attackers breach one system, segmentation prevents them from freely accessing everything else.

Essential segments for SMBs:

SegmentContainsAccess Policy
DMZWeb servers, email gateways, public-facing servicesInternet can reach specific services; limited internal access
Corporate LANUser workstations, printersInternet access via proxy; access to approved internal resources
Server VLANInternal servers, databases, file sharesNo direct internet; accessible only from authorised sources
Management VLANNetwork devices, admin interfacesHighly restricted; accessible only from admin workstations
Guest NetworkVisitor devices, personal phonesInternet only; no internal access whatsoever
IoT/OT NetworkCameras, sensors, industrial controlsIsolated; minimal required connectivity only

Your firewall enforces boundaries between these segments. A compromised workstation shouldn't automatically have access to your financial database. Proper firewall configuration and segmentation contain breaches to limited areas.

Rule 4: Enable SSL/TLS Inspection — See Inside Encrypted Traffic

Over 80% of web traffic is now encrypted. Without SSL inspection, your firewall is blind to threats hiding in HTTPS connections. Attackers know this and deliberately use encryption to evade detection.

Implementing SSL inspection:

  1. Generate or import a certificate authority (CA) that your firewall uses to decrypt traffic
  2. Deploy the CA certificate to all managed devices so they trust the firewall's certificates
  3. Create bypass rules for sensitive categories (banking, healthcare) where interception isn't appropriate
  4. Enable inspection for all other outbound HTTPS traffic

This allows your firewall to inspect encrypted traffic for malware, data loss, and policy violations. Yes, it adds complexity. But without it, you're defending with one eye closed.

Rule 5: Protect the Management Interface — Guard the Keys

The firewall management interface is a prime target. If attackers compromise it, they control your entire perimeter. Treat management access with extreme caution:

  • Never expose management interfaces to the internet — not even with "strong" passwords
  • Restrict access to specific management VLANs or IP addresses
  • Require multi-factor authentication for all administrative access
  • Use separate credentials from regular network accounts
  • Enable logging for all administrative actions
  • Review admin access quarterly — remove accounts no longer needed

A compromised firewall is worse than no firewall. The attacker can watch all traffic, modify rules silently, and maintain persistent access. Protect your firewall configuration interface accordingly.


Essential Firewall Rules for South African SMBs

Based on the local threat landscape, here are essential rules every South African business should implement:

Inbound Rules

RulePurposePriority
Block all by defaultFoundation of securityCritical
Allow established/relatedEnable stateful inspectionCritical
Allow specific services onlyWeb, email, VPN as neededRequired
Block known malicious IPsThreat intelligence feedsHigh
Geo-block high-risk countriesBlock regions you don't do business withRecommended
Rate limit connection attemptsPrevent brute force attacksRecommended

Outbound Rules

RulePurposePriority
Block all by defaultPrevent unauthorised egressCritical
Allow DNS to approved servers onlyPrevent DNS tunnellingCritical
Allow web via proxyEnable logging and filteringHigh
Block direct internet from serversForce proxy usageHigh
Allow specific cloud servicesMicrosoft 365, business SaaSRequired
Block file sharing protocolsPrevent data exfiltrationRecommended

Internal Segmentation Rules

RulePurposePriority
Block guest-to-corporateIsolate untrusted devicesCritical
Restrict server VLAN accessLimit who reaches sensitive systemsCritical
Isolate management networkProtect infrastructureCritical
Control IoT device communicationPrevent compromised device pivotingHigh
Log all cross-segment trafficEnable detection and forensicsHigh

Firewall Configuration Mistakes to Avoid

These common errors undermine security regardless of your hardware investment:

MistakeRiskSolution
"Any-any" allow rulesBypasses all protectionRemove immediately; create specific rules
Disabled loggingNo visibility into attacksEnable logging on all deny rules minimum
Default admin credentialsTrivial compromiseChange immediately; use strong unique passwords
Management on public interfaceDirect attack targetMove to isolated management network
Outdated firmwareKnown vulnerabilities exploitedPatch monthly; subscribe to vendor alerts
No rule review processRule bloat, forgotten permitsQuarterly reviews; document all rules
Overly broad service rulesUnnecessary exposureAllow only specific required ports/protocols
No outbound filteringMalware communicates freelyImplement outbound controls

One "temporary" any-any rule created for troubleshooting and forgotten can undo months of careful firewall configuration work. Document everything and review regularly.


Choosing the Right Firewall for Your SMB

South African SMBs have several solid options. The right choice depends on your size, technical capability, and budget:

SMB Firewall Comparison

Vendor/ProductBest ForApproximate Cost (ZAR)Key Strengths
Fortinet FortiGate (40F/60F)Small offices, branchesR8,000 - R25,000Excellent value, strong security fabric
SonicWall TZ seriesSMBs wanting simplicityR10,000 - R30,000Easy management, good support
Sophos XGS seriesMicrosoft-heavy environmentsR12,000 - R35,000Strong endpoint integration
WatchGuard FireboxCompliance-focused SMBsR15,000 - R40,000Excellent reporting, easy auditing
Palo Alto PA-400 seriesSecurity-first organisationsR25,000 - R60,000Industry-leading threat prevention
Ubiquiti UniFiBudget-conscious, tech-savvyR3,000 - R10,000Low cost, good basics, limited NGFW

Recommendations by business size:

  • 1-10 employees: FortiGate 40F, SonicWall TZ270, or Ubiquiti for basics
  • 10-50 employees: FortiGate 60F, Sophos XGS 107, SonicWall TZ370
  • 50-200 employees: FortiGate 100F, Sophos XGS 2100, Palo Alto PA-440

Remember: the best firewall poorly configured provides less protection than a basic firewall properly configured. Invest in firewall configuration expertise, not just hardware.


Ongoing Firewall Maintenance

Firewall configuration isn't a one-time project. Ongoing maintenance ensures continued protection:

Monthly Tasks

  • Review and apply firmware updates
  • Check threat intelligence feed updates
  • Review logs for anomalies or attacks
  • Verify backups of configuration
  • Check license expiration dates

Quarterly Tasks

  • Audit all firewall rules — remove unused rules
  • Review administrator accounts — remove departed staff
  • Test disaster recovery procedures
  • Review segmentation effectiveness
  • Update documentation

Annual Tasks

  • Conduct penetration test against perimeter
  • Review overall architecture and design
  • Assess whether hardware meets current needs
  • Benchmark against industry standards
  • Plan budget for upgrades or renewals

Document every change. Maintain a change log showing what was modified, when, why, and by whom. This audit trail proves invaluable during incident response and compliance reviews.


Integrating Firewall with Other Security Controls

Your firewall doesn't work in isolation. Maximum protection comes from integration with other security layers:

IntegrationBenefit
SIEM/Log ManagementCentralised visibility, correlation with other events
Endpoint ProtectionCoordinate blocking of threats at both perimeter and endpoint
Identity Access ManagementUser-based policies, authentication integration
Email SecurityBlock malicious IPs identified in email attacks
Vulnerability ScanningPrioritise patching based on exposure
Threat IntelligenceAutomated blocking of known malicious indicators

For Microsoft environments, integrating your firewall logs with Microsoft Sentinel provides powerful correlation and automated response capabilities.


Firewall Configuration and POPIA Compliance

For South African businesses, proper firewall configuration supports POPIA compliance in several ways:

  • Security safeguards: Demonstrates appropriate technical measures to protect personal information
  • Access control: Restricts who can reach systems containing personal data
  • Logging and monitoring: Provides audit trails of access attempts
  • Breach prevention: Reduces likelihood of reportable security compromises
  • Incident response: Logs assist investigation when incidents occur

When the Information Regulator asks what security measures you've implemented, a properly configured and documented firewall demonstrates due diligence.


The Cost of Poor Firewall Configuration

Inadequate perimeter security has real financial consequences:

ConsequenceImpact
Ransomware breachR17 million median ransom demand + R23 million recovery
Data breachR53.1 million average cost
Business interruptionOperational downtime, lost revenue
Regulatory penaltiesPOPIA fines up to R10 million
Reputational damageCustomer loss, brand impact
Cyber insurance claimsPremium increases or coverage denial

Compare this to the cost of proper firewall configuration: appropriate hardware (R10,000-R50,000 for most SMBs), professional setup, and ongoing maintenance. The investment is trivial compared to breach costs.


Next Steps for Your Organisation

Strengthen your firewall configuration today:

  1. Audit current rules — Can you justify every allow rule? Remove what you can't explain
  2. Implement default deny — If not already in place, this is your first priority
  3. Enable outbound controls — Don't let malware communicate freely
  4. Segment your network — Contain breaches before they spread
  5. Enable logging — You can't detect what you don't see
  6. Schedule regular reviews — Quarterly minimum for rule audits

Need help assessing your firewall configuration? Contact RSAT.online for a perimeter security assessment tailored to South African businesses.


About RSAT.online

RSAT.online provides practical cybersecurity guidance for South African small and medium businesses. From firewall assessments to network security audits, we help local organisations build robust perimeter defences against the 1,450 weekly attacks targeting SA businesses.

Contact us today →

Scroll to Top