Firewall Rules and Port Forwarding: The Most Common Mistakes in SMEs
Ten typical mistakes in firewall rules and port forwarding at SMEs, from open RDP to a firewall without logging, with BSI IT-Grundschutz requirements.
A firewall in an SME is rarely bought wrong, but often run wrong. The rules date from the installation years ago and have only grown longer since. Assessments almost always reveal the same ten mistakes, each described in the BSI situation report or the ENISA Threat Landscape as a real attack path.
Why firewall mistakes are expensive
In its 2025 situation report, the German Federal Office for Information Security (BSI) writes that known vulnerabilities in perimeter systems are far too often patched too late or not at all. Around 80 per cent of reported attacks targeted SMEs. ENISA’s Threat Landscape 2025 notes that exploitation of vulnerabilities accounted for 21.3 per cent of initial access and that initial access brokers continued to trade cheap VPN and RDP access.
The ten most common mistakes
- “Everything allowed except” instead of “everything blocked except”. NET.3.2 requires unambiguous rules defining which connections are permitted; all others are blocked. A default “any to any allow” rule from the test phase documents traffic, it does not control it.
- The forgotten test rule. A service provider briefly needs external access, the setup takes a week, the rule stays five years. Every rule therefore gets an owner, a purpose and an expiry date.
- RDP, SMB or database ports directly on the internet. Once port 3389 is open to the outside, automated attackers try passwords around the clock. The Brandenburg State Criminal Police Office describes a company encrypted in exactly this way. Remote access runs through a VPN with multi-factor authentication.
- Reachable services on the internal network. If the web server or customer portal sits on the same network as workstations and file server, an attacker who breaks in has access to everything. NET.1.1.A10 requires an external demilitarised zone (DMZ) for all internet-facing services.
- Outbound traffic without rules. Outbound, almost everything is usually allowed, yet that is the direction malware needs for command servers and exfiltration. NET.3.2.A2 prohibits unauthorised connections out of the protected network.
- Management via the workstation network. If the firewall’s web interface is reachable from every office VLAN, a captured password is enough to change the rules. NET.3.2.A6 requires protection of the administration interfaces, A18 a separate management network.
- Stateless filters and open ICMP rules. NET.3.2.A3 requires stateful filtering as a matter of principle, including for UDP and ICMP, and restrictive filtering of ICMP.
- No logging, no evaluation. NET.3.2.A9 requires at least the logging of rejected connections and failed logins, A23 integration into a monitoring concept with alerting. What modern detection adds is described in the article AI in network security.
- The firewall itself is not patched. Updates on perimeter systems are postponed for fear of downtime. Firewall updates belong in a fixed schedule with an emergency path, plus a configuration backup (NET.3.2.A32).
- The firewall replaces segmentation. A firewall at the internet gateway does not prevent malware from moving freely inside after a phishing click. NET.1.1.A5 requires clients and servers in different segments with a packet filter in between. What the individual components do is explained in the article Network security for businesses.
Putting a rule set in order
Cleaning up a rule set is not a reinstallation. Proven order:
- Inventory of the rules. Every inbound rule with purpose, owner and last usage date from the logs. Anything unassignable is disabled and removed after a grace period.
- Take administrative and file services off the internet. RDP, SMB, databases, web interfaces and remote maintenance move behind a VPN with multi-factor authentication.
- A DMZ for everything that must stay reachable. Web server, mail gateway and portals get their own zone with minimal inbound rules.
- Introduce outbound rules. First for servers, printers and building services, then for workstations.
- Separate internal zones. Workstations, servers, backup, management, guests and building services as VLANs with firewall rules in between.
- Switch on logging and alerting. With an evaluation someone actually reads or a service takes over.
- Regulate updates and backups. Fixed patch schedule, emergency path for critical vulnerabilities, configuration backup after every change.
- Follow-up. Once a year or after every major project, a target-actual comparison (NET.1.1.A15).
These steps are part of the basics described in the article Protection against hacker attacks: 12 concrete measures.
Key points
- The firewall decides what attack surface a company presents: only explicitly permitted connections pass, in both directions.
- Administrative and file services never belong directly on the internet, reachable services belong in a DMZ, firewall management in its own management network.
- Every rule needs a purpose, an owner and an expiry date; logging, updates and an annual target-actual comparison keep the rule set current.
How DEVACON supports companies with the assessment and clean-up of firewall rule sets is described on the page Cybersecurity.
Sources
- Federal Office for Information Security (BSI): Die Lage der IT-Sicherheit in Deutschland 2025, reporting period 1 July 2024 to 30 June 2025, bsi.bund.de/lagebericht
- BSI IT-Grundschutz-Kompendium, Edition 2023, module NET.3.2 Firewall, bsi.bund.de
- BSI IT-Grundschutz-Kompendium, Edition 2023, module NET.1.1 Netzarchitektur und -design, bsi.bund.de
- ENISA: Threat Landscape 2025, published 1 October 2025, analysis of 4,875 incidents from 1 July 2024 to 30 June 2025, enisa.europa.eu
- Brandenburg State Criminal Police Office: Lagebild Cybercrime im Land Brandenburg 2024, published October 2025, polizei.brandenburg.de
This article comes from the DEVACON blog and was editorially revised for the new website.