Every firewall allow rule creates a permitted path
Every rule you add is a route somebody can use, including somebody you did not have in mind.
Rules accumulate for good reasons: a project needed it, a supplier required it, something broke. They are rarely removed, because nobody knows what depends on them and removal has no deadline. A firewall's ruleset after a decade is a fair map of every temporary arrangement the organisation ever made.
More on Network segmentation
- Segmentation limits paths, not compromise itselfBulkheads, not armour
- Flat networks turn local trust into broad reachabilityOne floor, no walls
- Microsegmentation moves boundaries closer to workloadsMove the fence inwards
- Management paths can bypass segmentationOver the checkpoint
- Default deny makes new paths deliberateNothing moves until a lever is pulled
- Network zones should reflect trust and functionZones follow the job
