Every firewall allow rule creates a permitted path

Every rule you add is a route somebody can use, including somebody you did not have in mind.

Rules accumulate for good reasons: a project needed it, a supplier required it, something broke. They are rarely removed, because nobody knows what depends on them and removal has no deadline. A firewall's ruleset after a decade is a fair map of every temporary arrangement the organisation ever made.

More on Network segmentation