Firewall Security

How to Tell Whether Your Business Firewall Is Being Monitored

A firewall can block unwanted traffic without anyone actively reviewing what is happening. Learn the difference between owning a firewall and monitoring the activity it records.

There is an important difference between having a firewall and monitoring the firewall.

A firewall may enforce rules automatically, but enforcement alone does not tell the business what attacks are occurring, which events are unusual, or whether a security incident requires investigation.

Difference between firewall enforcement and firewall monitoring A firewall blocks or allows traffic, while a monitoring system collects events and produces actionable alerts. Enforcement is not the same as monitoring Internet traffic Firewall Allow or block Monitor events Review and respond
A firewall can enforce rules automatically, while monitoring explains what is happening and whether action is required.

The basic distinction

A firewall can operate without anyone watching it

Rule enforcement is useful, but it is only one part of security visibility.

A typical firewall may contain rules such as allowing established connections, allowing HTTPS, allowing VPN access, and denying unsolicited inbound traffic.

  • 01

    Automatic enforcement

    Rules can be applied without human review

    • Allow established connections
    • Allow HTTPS traffic
    • Allow approved VPN connections
    • Deny unsolicited inbound traffic

    These rules may protect the network, but they do not explain whether an attacker is repeatedly probing the environment or whether a legitimate account is being misused.

Blocking traffic does not eliminate the need for visibility

The business still needs to know what was blocked, what was allowed, and whether several events are connected.

What monitoring means

Firewall monitoring involves collecting and analyzing events

The exact data available depends on the firewall, its configuration, and the monitoring service connected to it.

Meaningful monitoring generally involves collecting relevant firewall events, analyzing them for unusual patterns, and generating alerts when activity requires attention.

  • 01

    Events worth monitoring

    Look beyond blocked connections

    • Blocked connections
    • Allowed connections
    • Authentication events
    • VPN connections
    • Configuration changes
    • Administrative logins
    • Port scans
    • Connection anomalies

Question one

Ask where the logs go

Knowing that a firewall creates logs is not the same as knowing that anyone reviews them.

A simple test is to ask where firewall logs are stored. If the answer is that the firewall has logs, the next question should be: “Who reviews them?”

Firewall logs are sent to centralized monitoring Firewall events are collected by a centralized logging platform, where they can be reviewed and correlated with other security events. Firewall log flow Firewall Central logging Human review Investigation
Centralized logging makes it easier to retain, review, and correlate firewall activity.

Logging without review is limited visibility

If nobody reviews firewall events, the organization has logs but not meaningful continuous monitoring.

Question two

Ask how alerts are generated

A monitored firewall should have defined criteria for generating alerts.

Alert rules should reflect the business's systems, users, expected traffic, and risk tolerance. They should also distinguish routine activity from behavior that requires investigation.

  • 01

    Possible alert conditions

    Examples of activity that may require attention

    • Repeated authentication failures
    • Administrative login from an unexpected source
    • Large numbers of blocked connections
    • Unexpected outbound traffic
    • Firewall configuration changes
    • Unusual VPN activity
    • Repeated connections to suspicious destinations

Question three

Ask what happens after an alert

An alert is useful only when there is a defined process for reviewing and responding to it.

A security monitoring process should explain how alerts are classified, who receives them, how quickly they are reviewed, and which response actions are available.

1

Define the alert

Establish which firewall events or combinations of events should generate an alert.

2

Notify the right person

Identify who receives the alert and who is responsible for deciding whether further investigation is needed.

3

Review the evidence

Collect relevant source, destination, service, timing, action, and related-event information.

4

Determine the response

Decide whether the activity is routine, suspicious, or an incident requiring containment and escalation.

Actionable alerts

Monitoring should produce useful information

A useful alert should explain more than “firewall event detected.”

  • 01

    Alert context

    Include the information needed to make a decision

    • Source
    • Destination
    • Service
    • Time
    • Firewall action
    • Number of attempts
    • Related events
    • Severity
    • Recommended next step
    Quality test

    A recipient should be able to understand why the event matters and what should happen next.

Centralized visibility

Check whether logs are centralized

If firewall logs remain exclusively on the firewall, historical investigation can become difficult.

Centralized logging allows firewall activity to be correlated with other events, such as DNS requests, authentication failures, intrusion-detection alerts, and endpoint activity.

Firewall events are correlated with other security telemetry A blocked firewall connection is combined with DNS, authentication, intrusion detection, and endpoint events in a centralized monitoring platform. One firewall event rarely tells the whole story Blocked connection Central logging Related events DNS request Authentication failure IDS alert Endpoint event
Centralized logging can connect firewall activity with related security events from across the environment.

Question four

Ask whether monitoring is continuous

A monthly review is different from continuous monitoring. Both may have value, but they serve different purposes.

Businesses should understand exactly what their service provides and how quickly activity is reviewed.

  • 01

    Monitoring model

    Understand what happens between reviews

    • Real-time alerting
    • Scheduled review
    • Automated detection
    • Manual investigation
    • Incident response
    • Periodic reporting
    Important distinction

    A periodic report may summarize past activity, while continuous monitoring is designed to identify events while they are occurring.

Firewall monitoring checklist

Questions to ask your provider

  • 01

    Where are firewall logs stored?

    Confirm whether logs remain on the firewall or are forwarded to a centralized monitoring environment.

  • 02

    Who reviews the logs?

    Identify whether review is performed by an automated system, security analyst, internal employee, or service provider.

  • 03

    How quickly are alerts reviewed?

    Understand whether alert review occurs continuously, during business hours, or on a scheduled basis.

  • 04

    What information does an alert contain?

    Alerts should include enough context to support investigation and determine the appropriate next step.

  • 05

    What happens after an alert?

    Confirm who investigates, who determines whether an incident occurred, and which response actions are available.

The takeaway

Know what your firewall is seeing

A firewall can protect a business by enforcing traffic rules, but protection is only one part of security. Meaningful monitoring requires logs, defined alert criteria, centralized visibility, human or automated review, and a response process.

Businesses should know what activity is being recorded, who reviews it, how quickly alerts are handled, and whether firewall events are correlated with other security telemetry.

Improve your firewall visibility

Turn firewall events into actionable information

A managed security monitoring service can collect firewall events, correlate them with other security telemetry, and provide alerts when activity requires attention.

Request a Small Business Security Assessment