Sentrix

Services · Implementation

Network security: we review every rule, not just new ones

Firewalls, segmentation and remote access (VPN, ZTNA) deployed on the vendor you already have, then the full rule set reviewed for least privilege and tested.

Why this matters

Rules accumulate. Reviews don't always keep up. A firewall configured correctly on day one rarely stays that way: rules get added under pressure, exceptions get forgotten, and nobody circles back to remove what's no longer needed.

Forgotten permissive rules

A rule opened for a one-time vendor request often outlives the request by years.

Legacy rules nobody owns

Rules referencing decommissioned systems stay active because no one is confident it's safe to remove them.

Segmentation on paper only

A network diagram can show clean segmentation while the actual rule set still allows lateral movement.

Remote access as an afterthought

A VPN set up quickly during a transition period rarely gets revisited once things stabilize.

What sets this apart

We review every rule, not just the new ones. We don't just deploy your firewall and segmentation strategy: we go back and review the full rule set for least privilege, catching the forgotten permissive or legacy rules nobody remembers approving, and hand you a specific action for each one.

  • Firewall rule set: reviewed end to end for least privilege, not just the rules we added.
  • Segmentation: confirmed to actually block lateral movement, not just look correct on a diagram.
  • Legacy and permissive rules: flagged with the business justification checked, not assumed.
  • Remote access: VPN and ZTNA configurations tested against real connection attempts.

Sample validation findings

Illustrative examples; they do not describe a specific client.

  • High: an outbound firewall rule permits unrestricted RDP (3389) to the internet. Action: restrict RDP egress to the management subnet and require VPN for remote access.
  • High: a rule referencing a decommissioned VPN concentrator is still active and unrestricted. Action: remove the rule after confirming no dependent traffic remains.
  • Medium: the finance VLAN can still reach the guest network due to an overly broad segmentation rule. Action: tighten the segmentation rule to explicitly deny guest-to-finance traffic.
  • Low: a vendor-access rule opened eighteen months ago has no documented owner or expiry. Action: assign an owner and set a review date, or remove the rule if no longer needed.

What you get

Firewall configured and rules reviewed

Your next-generation firewall deployed or optimized, and the full rule set reviewed end to end for least privilege, with an owner and a justification for every rule that stays.

Tested segmentation

Logical network separation that limits lateral movement, confirmed by tests rather than by a diagram.

Secure remote access

A VPN or Zero Trust Network Access (ZTNA) solution set up or reviewed, and tested against real connection attempts.

A report with one action per rule in breach

Every permissive, legacy or ownerless rule comes with a specific action: tighten, assign, remove.

Our approach

  1. Assessment. Analysis of your existing network infrastructure, the rule set in place and the remote access paths, to scope the engagement.
  2. Design. A tailored network security architecture: firewall rules, segmentation strategy and remote access solution (VPN or ZTNA).
  3. Deployment. Firewall configuration, segmentation and remote access set up, planned around your maintenance windows and tested before cutover.
  4. Review and report. End-to-end review of the full rule set, segmentation tested against lateral movement, remote access tested; hand-off of the report with a specific action for each rule in breach.

Works with what you have

Optimized before replaced. Next-generation firewalls, network segmentation, VPN, Zero Trust Network Access (ZTNA): in most cases, we optimize your existing firewall and remote access vendor before recommending a replacement.

After the engagement

An implementation engagement is a defined project. The quarterly firewall rule review is part of the Managed Security Operations check framework. The boundary protection requirements of CPCSC (control 03.13.01) and the TGV criteria rely on this kind of review; remote access ties in with the identity and access service.

Control who, and what, gets in.

Let's talk about your current network architecture and access paths.

Contact us

Frequently asked questions

Will this require downtime?
We plan network changes around maintenance windows and test configurations before cutover whenever possible to minimize disruption. Legacy rules are removed only after confirming no dependent traffic remains, and segmentation is verified against real connection attempts rather than on a diagram.
Do you work with our existing firewall vendor?
In most cases, yes: we optimize your existing firewall and remote access vendor before recommending a replacement. What makes the difference is not the equipment, but the end-to-end review of the full rule set for least privilege, including the permissive or legacy rules nobody remembers approving.
What is Zero Trust Network Access, in plain terms?
Instead of trusting anyone inside your network perimeter, every access request is verified, regardless of where it comes from. It replaces or complements a traditional VPN with something far harder to abuse if credentials are stolen. We test VPN and ZTNA configurations against real connection attempts before relying on them.
What do you review after deployment?
Four points: the firewall rule set, reviewed end to end for least privilege and not just the rules we added; segmentation, confirmed to actually block lateral movement; legacy and permissive rules, flagged with the business justification checked; and remote access, tested against real connection attempts. Every rule found in breach gets a specific action.
What happens after the engagement?
The implementation engagement is a defined project that ends with the rule review and the hand-off of the report. The quarterly firewall rule review, configuration drift detection and remediation tracking can then be handed off to our Managed Security Operations team, on a documented cadence, with no mandatory recurring commitment.

Let's talk about your compliance program.

Last updated: 2026-09-17