There is an important difference between having a firewall and monitoring the firewall.
A firewall may enforce rules automatically, but enforcement alone does not tell the business what attacks are occurring, which events are unusual, or whether a security incident requires investigation.
The basic distinction
A firewall can operate without anyone watching it
Rule enforcement is useful, but it is only one part of security visibility.
A typical firewall may contain rules such as allowing established connections, allowing HTTPS, allowing VPN access, and denying unsolicited inbound traffic.
-
01
Automatic enforcement
Rules can be applied without human review
- Allow established connections
- Allow HTTPS traffic
- Allow approved VPN connections
- Deny unsolicited inbound traffic
These rules may protect the network, but they do not explain whether an attacker is repeatedly probing the environment or whether a legitimate account is being misused.
Blocking traffic does not eliminate the need for visibility
The business still needs to know what was blocked, what was allowed, and whether several events are connected.
What monitoring means
Firewall monitoring involves collecting and analyzing events
The exact data available depends on the firewall, its configuration, and the monitoring service connected to it.
Meaningful monitoring generally involves collecting relevant firewall events, analyzing them for unusual patterns, and generating alerts when activity requires attention.
-
01
Events worth monitoring
Look beyond blocked connections
- Blocked connections
- Allowed connections
- Authentication events
- VPN connections
- Configuration changes
- Administrative logins
- Port scans
- Connection anomalies
Question one
Ask where the logs go
Knowing that a firewall creates logs is not the same as knowing that anyone reviews them.
A simple test is to ask where firewall logs are stored. If the answer is that the firewall has logs, the next question should be: “Who reviews them?”
Logging without review is limited visibility
If nobody reviews firewall events, the organization has logs but not meaningful continuous monitoring.
Question two
Ask how alerts are generated
A monitored firewall should have defined criteria for generating alerts.
Alert rules should reflect the business's systems, users, expected traffic, and risk tolerance. They should also distinguish routine activity from behavior that requires investigation.
-
01
Possible alert conditions
Examples of activity that may require attention
- Repeated authentication failures
- Administrative login from an unexpected source
- Large numbers of blocked connections
- Unexpected outbound traffic
- Firewall configuration changes
- Unusual VPN activity
- Repeated connections to suspicious destinations
Question three
Ask what happens after an alert
An alert is useful only when there is a defined process for reviewing and responding to it.
A security monitoring process should explain how alerts are classified, who receives them, how quickly they are reviewed, and which response actions are available.
Define the alert
Establish which firewall events or combinations of events should generate an alert.
Notify the right person
Identify who receives the alert and who is responsible for deciding whether further investigation is needed.
Review the evidence
Collect relevant source, destination, service, timing, action, and related-event information.
Determine the response
Decide whether the activity is routine, suspicious, or an incident requiring containment and escalation.
Actionable alerts
Monitoring should produce useful information
A useful alert should explain more than “firewall event detected.”
-
01
Alert context
Include the information needed to make a decision
- Source
- Destination
- Service
- Time
- Firewall action
- Number of attempts
- Related events
- Severity
- Recommended next step
Quality testA recipient should be able to understand why the event matters and what should happen next.
Centralized visibility
Check whether logs are centralized
If firewall logs remain exclusively on the firewall, historical investigation can become difficult.
Centralized logging allows firewall activity to be correlated with other events, such as DNS requests, authentication failures, intrusion-detection alerts, and endpoint activity.
Question four
Ask whether monitoring is continuous
A monthly review is different from continuous monitoring. Both may have value, but they serve different purposes.
Businesses should understand exactly what their service provides and how quickly activity is reviewed.
-
01
Monitoring model
Understand what happens between reviews
- Real-time alerting
- Scheduled review
- Automated detection
- Manual investigation
- Incident response
- Periodic reporting
Important distinctionA periodic report may summarize past activity, while continuous monitoring is designed to identify events while they are occurring.
Firewall monitoring checklist
Questions to ask your provider
-
01
Where are firewall logs stored?
Confirm whether logs remain on the firewall or are forwarded to a centralized monitoring environment.
-
02
Who reviews the logs?
Identify whether review is performed by an automated system, security analyst, internal employee, or service provider.
-
03
How quickly are alerts reviewed?
Understand whether alert review occurs continuously, during business hours, or on a scheduled basis.
-
04
What information does an alert contain?
Alerts should include enough context to support investigation and determine the appropriate next step.
-
05
What happens after an alert?
Confirm who investigates, who determines whether an incident occurred, and which response actions are available.
The takeaway
Know what your firewall is seeing
A firewall can protect a business by enforcing traffic rules, but protection is only one part of security. Meaningful monitoring requires logs, defined alert criteria, centralized visibility, human or automated review, and a response process.
Businesses should know what activity is being recorded, who reviews it, how quickly alerts are handled, and whether firewall events are correlated with other security telemetry.
Improve your firewall visibility
Turn firewall events into actionable information
A managed security monitoring service can collect firewall events, correlate them with other security telemetry, and provide alerts when activity requires attention.
Request a Small Business Security Assessment