CriticalPA-001 · 1 place
The rule uses 'any' in every field, which is an overly broad permission
This rule allows anyone to access any internal resource, making a breach trivial if a single password is stolen.
First step: Policies > Security: check the rule's traffic in Monitor > Traffic, then restrict source, destination, application and service to what is actually used.
~half dayfirewall admin
CriticalPA-006 · 1 place
The rule allows an insecure application from an untrust zone
Exposing management ports like SSH or RDP to the internet allows attackers to attempt brute-force logins to your servers.
First step: Policies > Security: Change the source zone or add a specific source IP to restrict access.
~15 minfirewall admin
CriticalPA-009 · 1 place
The interface management profile allows access via HTTP or TELNET
Enabling HTTP or Telnet sends management credentials in plain text, allowing them to be stolen by anyone on the path.
First step: Network > Network Profiles > Interface Mgmt: edit the profile and untick HTTP and Telnet (keep HTTPS/SSH only where needed).
~15 minfirewall admin
CriticalPA-011 · 1 place
The SNMP community string uses an insecure value
Default SNMP strings are well-known to attackers and can be used to leak sensitive device information.
First step: Device > Setup > Operations > SNMP Setup: use SNMPv3, or replace the community string with a long random value.
~15 minfirewall admin
HighPA-002 · 4 places
The rule uses 'any' for application, which is an overly broad permission
Allowing any application enables attackers to use non-standard ports to bypass security controls and hide malicious traffic.
First step: Policies > Security: use the rule's App-ID data (Policy Optimizer) to replace 'any' in Application with the specific applications seen.
~half dayfirewall admin
- Legacy-FTP-Partners
- Temp-Vendor-Access
- Allow-Any-Catchall
- Old-Backup-Any
MediumPA-008 · 11 places
No zone-protection-profile is defined for the zone
Missing zone protection leaves the firewall vulnerable to flood attacks and reconnaissance scans on that interface.
First step: Network > Network Profiles > Zone Protection: create a profile, then assign it under Network > Zones for this zone.
~15 minnetwork team
- untrust
- trust
- dmz
- mgmt
- vpn
- lab
- guest
- users
- voice
- iot
- +1 more (11 in total)
MediumPA-005 · 9 places
The rule does not log at session end (log-end is unset or 'no')
If logs are not enabled, you will have no record of who accessed your network during a security incident.
First step: Policies > Security: Edit the rule and check the 'Log at Session End' box.
~15 minfirewall admin
- Legacy-FTP-Partners
- Temp-Vendor-Access
- Legacy-SSH-Partners
- Allow-Mgmt-Ping
- Allow-Voice-SIP
- Allow-Mgmt-Web
- Allow-Users-SMB
- Allow-Users-Ssh-Lab
- Old-Voice-Trunk
MediumPA-004 · 4 places
The rule has no security profile group or profiles configured
Without security profiles, the firewall cannot detect or block viruses, spyware, or known vulnerabilities in the traffic.
First step: Objects > Security Profile Groups: create a group (antivirus, anti-spyware, vulnerability, URL), then attach it in the rule's Actions tab > Profile Setting.
~1 hsecurity team
- Allow-Mgmt-Ping
- Allow-Mgmt-Web
- Allow-Any-Catchall
- Old-Voice-Trunk
MediumPA-003 · 3 places
The rule uses 'any' for service, which is an overly broad permission
Using 'any' service allows traffic on any port, increasing the attack surface for services that should be restricted.
First step: Policies > Security: Change the Service column from 'any' to 'application-default' or a specific port.
~15 minfirewall admin
- Legacy-FTP-Partners
- Temp-Vendor-Access
- Allow-Any-Catchall
MediumPA-018 · 3 places
The rule is never evaluated because an earlier rule already allows all traffic
A broader rule above catches this traffic first, so the restriction you think is in place never applies and more traffic is allowed than intended.
First step: Policies > Security: Move the specific rule above the general 'any' rule or delete it.
~15 minfirewall admin
- Legacy-Backup-Partners
- Old-Voice-Trunk
- Deny-All-Log
MediumPA-013 · 1 place
Syslog server profiles are not defined
Without syslog forwarding, logs are only stored locally and can be lost or deleted by an attacker.
First step: Device > Server Profiles > Syslog: add your log server, then use it in Objects > Log Forwarding and in Device > Log Settings.
~1 hsecurity team
LowPA-019 · 4 places
A management service (https/ssh/http/telnet) is enabled on the interface
Management interfaces open to the world are targets for constant brute-force attacks and vulnerability scanning.
First step: Network > Network Profiles > Interface Mgmt: add only your management networks under Permitted IP Addresses, or remove management services from this interface.
~15 minfirewall admin
- ethernet1/1(untrust)
- ethernet1/2(trust)
- ethernet1/3(dmz)
- ethernet1/4(mgmt)
LowPA-007 · 3 places
Rule is disabled
Disabled rules clutter the configuration and can lead to confusion or accidental activation of insecure policies.
First step: Policies > Security: Review the rule; delete it if it is no longer needed.
~15 minfirewall admin
- Old-Partner-RDP
- Legacy-Telnet-Mgmt
- Temp-Debug-Any
LowPA-017 · 3 places
The rule has no description
Rules without descriptions make it difficult for other engineers to understand the business purpose of the traffic.
First step: Policies > Security: Add a clear description explaining why the rule exists and who requested it.
~15 minfirewall admin
- Allow-Users-DNS
- Allow-Voice-SIP
- Allow-Mgmt-Web
LowPA-012 · 1 place
The administrator account uses the default name 'admin'
Using the default 'admin' username makes it easier for attackers to guess the login credentials.
First step: Device > Administrators: create a named superuser account for each admin, test it, then delete or disable the default 'admin' account.
~15 minfirewall admin
LowPA-014 · 1 place
NTP servers are not defined
Incorrect system time can break authentication (like LDAP/SAML) and make log timestamps unreliable for forensics.
First step: Device > Setup > Services > NTP: add two reliable NTP servers.
~15 minnetwork team
LowPA-015 · 1 place
No login banner is defined
A missing login banner fails to provide legal warning to unauthorized users, which may be required for compliance.
First step: Device > Setup > Management > General Settings: enter a legal warning in Login Banner.
~15 minfirewall admin