- The situation
- An ageing Cisco ASA pair was carrying the perimeter for a regulated environment, with policy that had
accreted across years of one-off changes and no reliable record of what any given rule was for.
- What we did
- Audited the existing rule base against actual observed traffic before touching anything, rebuilt policy on
a Palo Alto HA pair under Panorama, and cut over in stages with a tested rollback at each one. Rules nobody
could justify were retired rather than carried forward.
- Where it landed
- The estate came out with a perimeter the security team can actually reason about, and change control
that no longer depends on institutional memory.