The firewall meme, and the rule nobody closed
Opened for one afternoon by somebody in a hurry who has since left the company. The ticket is closed. The rule is not.
Every firewall has one. It was opened on a Tuesday to get something working, by somebody who meant to close it on the Wednesday, and the change ticket was marked done because the thing that was broken had started working. The rule outlived the project, the supplier and in most cases the person who asked for it.
This is the ordinary shape of firewall drift, and it is not carelessness so much as arithmetic: rules are added by people under pressure and removed by nobody in particular. A ruleset grows until it is longer than anyone will read, and a rule nobody will read is a rule nobody can judge.
The fix is dull and it works. Every rule gets an owner and a reason recorded at the moment it is opened, because neither is recoverable afterwards. Anything opened as temporary gets an expiry date rather than an intention. And the set is reviewed on a schedule, looking for rules with no owner, no traffic, or a source that no longer exists. Firewall vendors and the CIS benchmarks both put periodic rule review in their baseline configuration advice, for exactly this reason.
The court's own version of this failure is recorded elsewhere, at greater length and with a medal involved.
The ceremony of the Idiot Admin →