Back to category

Week 1

Investigate a Perimeter Firewall Misconfig Exposing a Production Database Server

Beginner
Network Security Analyst
Security Analyst
Network Engineer
NIST SP 800-41
CIS 18 CSC 12
PCI DSS 4.0 §1
NIST CSF PR.AC-5
NIST CSF 2.0
NIST SP 800-207 (Zero Trust)
Firewall Rule Analysis
Perimeter Exposure Assessment
Palo Alto PAN-OS
Network Segmentation
Zero Trust Segmentation

Client Background

Belle Maison Retail is a 1,400-employee specialty home-goods retailer with 80 stores across the US and a single corporate HQ. Their internal network was originally built flat; an internal security project to segment the network is half complete. A Palo Alto Networks NGFW protects the internet edge and the data center perimeter.

Business Environment

Single corporate HQ, two data centers (primary and DR), flat network between store VLANs and corporate subnets. Network/security team of four. Palo Alto running PAN-OS 10.2 with App-ID/Content v11, managed by Panorama. Last firewall rule review was 14 months ago.

Security Incident

SOC alerted on 2026-07-18 with outbound traffic from production DB server (10.30.20.50) reaching an unknown VPS host. Investigation revealed the DB server's SSH listener has a public-facing ALLOW rule admitted inbound from 0.0.0.0/0 — an April 2026 routine emergency change exceeded its intended scope and was never reverted.

Scope

Palo Alto NGFW ruleset at the data center perimeter, the affected DB server network behavior, segmentation design between VLAN30-DB and corporate VLAN. Endpoint telemetry is out of scope.

Objectives

  • Triage the firewall misconfig and identify the rule(s) responsible for the SSH exposure
  • Quantify inherent risk and recommend remediation with interim mitigations
  • Harden the perimeter rulebase and change-management process to prevent recurrence
  • Evaluate identity-based filtering (MFA / Zero Trust segmentation) at the perimeter as a compensating control equal in importance to closing the exposed SSH rule.

Required Deliverables

Perimeter firewall exposure report with risk-ranked rules
Segmentation gap analysis with recommended VLAN/firewall changes
Hardening plan for DB and perimeter rules with a 24h SLA
3 hrs estimated