Week 1
Investigate a Perimeter Firewall Misconfig Exposing a Production Database Server
Client Background
Belle Maison Retail is a 1,400-employee specialty home-goods retailer with 80 stores across the US and a single corporate HQ. Their internal network was originally built flat; an internal security project to segment the network is half complete. A Palo Alto Networks NGFW protects the internet edge and the data center perimeter.
Business Environment
Single corporate HQ, two data centers (primary and DR), flat network between store VLANs and corporate subnets. Network/security team of four. Palo Alto running PAN-OS 10.2 with App-ID/Content v11, managed by Panorama. Last firewall rule review was 14 months ago.
Security Incident
SOC alerted on 2026-07-18 with outbound traffic from production DB server (10.30.20.50) reaching an unknown VPS host. Investigation revealed the DB server's SSH listener has a public-facing ALLOW rule admitted inbound from 0.0.0.0/0 — an April 2026 routine emergency change exceeded its intended scope and was never reverted.
Scope
Palo Alto NGFW ruleset at the data center perimeter, the affected DB server network behavior, segmentation design between VLAN30-DB and corporate VLAN. Endpoint telemetry is out of scope.
Objectives
- Triage the firewall misconfig and identify the rule(s) responsible for the SSH exposure
- Quantify inherent risk and recommend remediation with interim mitigations
- Harden the perimeter rulebase and change-management process to prevent recurrence
- Evaluate identity-based filtering (MFA / Zero Trust segmentation) at the perimeter as a compensating control equal in importance to closing the exposed SSH rule.
Required Deliverables