Skip to content
Breakpoint Labs
Authorised systems only. Breakpoint Labs works only on authorised scope, so rules of engagement are agreed in writing first.

Coverage note

Firewall penetration testing: do the rules really hold?

Firewall penetration testing checks whether your firewalls enforce the design on paper. So it tests what actually passes through, not only what the rule base says.

  • Manual exploit chains
  • PTES and the OWASP testing guide
  • Authorised scope only
Firewall penetration testing: agree the scope, test with authorisation and evidence and retest

Why firewall penetration testing matters

Rule bases grow for years. However, nobody removes the temporary rule added for a past project. Therefore real exposure drifts away from the intended design.

The firewall's own management interface is also a target. Also, a misconfigured management path can undo every other control.

What firewall penetration testing covers

The test checks the rules from both sides. For example, which services are reachable from the internet and between internal zones.

  • Exposed services from the internet
  • Segmentation between internal zones
  • Management interface exposure
  • Rule base hygiene and stale rules
  • Logging of denied and allowed traffic

Firewall penetration testing readiness check

Tick what is already true. Open items go into the written rules of engagement.

Your result appears here as you tick, so you can see what is still open.

Scoping firewall penetration testing

Zone count drives effort. However, sharing the rule base shortens the work.

QuestionEffect on scope
How many firewalls?Each is assessed
How many zones?More zones, more paths
Cloud security groups?Reviewed alongside
Rule base export available?Speeds up review

Authorisation and safety

Testing runs only under written rules of engagement. Also, no load or denial-of-service testing is performed, because availability matters most.

In addition, a change freeze during testing keeps results accurate.

Evidence, fees and retest

Findings come with evidence and a fix, following NIST SP 800-115.

Full engagements run from $35,000 to $120,000, while the floor is $25,000. Also, the bounded Attack Surface Diagnostic starts at $4,500. Moreover, its fee is credited in full against a full engagement commissioned within ninety days.

Also schedule rule reviews between tests. Because rules drift steadily, a review every six months keeps the base close to design. So each rule needs an owner and a reason. In addition, remove rules with no recent traffic after checking with their owners, because unused rules are easy openings. As a result, the next test finds a tidier estate.

Firewall penetration testing questions

Is firewall penetration testing the same as a rule review?

No. A review reads the rules, while testing checks what really passes.

Can firewall penetration testing cause outages?

No load testing is done, and windows are agreed.

Does firewall penetration testing cover cloud security groups?

If agreed in scope, yes.

Who leads the work?

A senior penetration hacker.

Related guides

Send the brief for firewall penetration testing

Describe your zones and firewalls. The penetration hacker who would lead the work replies with a written scope and one fixed fee.

Send the brief