Introduction
An unexpected critical situation arose at a medium-sized company when the chief IT officer, who was the only person with administrative access to the company’s firewall, became unavailable. The login details and configuration documents had not been recorded in a password manager or in any other form, so the firewall became completely inaccessible. It became essential to reconfigure the system, which formed the basis of the company’s network communications and security policies; however, neither documentation nor backups were available.
Our company was commissioned to restore the network infrastructure and modernise the security system.
Current situation and challenges
The previous firewall was running on outdated hardware, and there was no access to its software configuration. Network traffic rules, port openings, NAT settings, VPN connections and security zones all remained hidden, meaning that neither the logic behind the operating services nor their security levels was known.
This situation posed a serious risk:
- IT security risks (open or faulty rules),
- Risk of service outages (disruption to business processes),
- Compliance shortcomings (lack of documentation and access control).
The task was twofold: to rebuild the system without disrupting day-to-day operations, and to design a modern, well-documented and sustainable security infrastructure.
Objective and approach
Our aim was to:
- We are redesigning the set of rules governing the firewall and the perimeter network in line with the company’s current requirements.
- Let’s ensure high availability (HA).
- Let’s create a transparent, well-documented, modern network security environment.
- We are laying the foundations for future maintainability and access management.
Our approach was gradual, collaborative and documentation-based.
The implementation process
1. Survey
As a first step, we conducted interviews with local IT specialists and system administrators to establish which network connections, systems and services needed to be operated through the firewall.
At the same time, we used network diagnostic tools to map out the existing infrastructure (IP ranges, traffic patterns, access points).
2. Planning
Based on the information gathered, we have drawn up the configuration plan, which:
- detailed the logical separation of the expected zones (internal, DMZ, guest and VPN zones);
- set out the traffic flow directions and access rules;
- complied with the latest security guidelines (e.g. the „least privilege” principle, logging, TLS inspection, an aggressive port-closing policy).
During the planning phase, representatives from all relevant departments (e.g. development, finance, logistics) helped to identify which services required external links.
3. Preparing the infrastructure
To ensure redundancy, we have procured a dual physical firewall system, which we have installed in a high-availability (HA) configuration.
The modern software environment ensured future scalability and the documented management of rules.
4. Implementation and testing
We configured the new system in accordance with the configuration plan and then carried out a test run to check that it was working correctly.
During testing, we monitored key applications and services (e.g. ERP, email, remote access, web portals).
We rectified any errors that arose immediately and then documented them.
Following the trial run, we gradually transitioned to full-scale operation, whilst remaining on standby at all times to resolve any new faults.
Results
As a result of several months’ work, we have succeeded in establishing a completely new, secure and transparent firewall infrastructure.
Features of the new system:
- Redundant, fault-tolerant operational reliability (HA system).
- Thoroughly documented firewall rules and configurations.
- Introduction of centralised password and access management.
- Integration of logging, monitoring and change tracking.
- A system environment that is easy for the company’s staff and IT specialists to understand and maintain.
Lessons learnt and recommendations
During the project, it became clear that:
- Documenting access management is of critical importance;
- At least two people with the appropriate authorisation must be aware of the administrative access details;
- The use of password management systems (e.g. 1Password, Bitwarden) is essential for the secure storage of login details;
- It is recommended that you carry out regular backups and export your configuration;
- Knowledge-sharing and organisational accountability are essential in IT security.
If the company had implemented these practices earlier, the whole incident could have been avoided and hundreds of working hours could have been saved.
Summary
This case clearly illustrates that organisational and human processes are actually what underpin technological stability. The loss of a single person’s knowledge can bring an organisation to a standstill for months on end if that knowledge has not been shared and documented.
The project was ultimately completed successfully, and the company now has a modern, reliable and sustainable security infrastructure that provides a foundation for future developments and security strategies.