Firewall rule review: finding the rule that blocks traffic
For network technicians, firewall administrators and MSP engineers who already know zones, deny by default and first-match rule order (see Designing firewall rule sets) and are now asked "which rule is blocking this?". You'll work out which rule set a connection meets from its ingress interface, direction and NAT, predict the matching rule under first-match (quick) and last-match evaluation and the default deny, prove it with logs, tracker IDs, state tables, FortiGate's Policy match and debug flow, rule out causes that only look like a firewall block, and write a finding that names the rule, the evidence and the smallest change. Examples use pfSense, OPNsense and FortiGate, grounded in their documentation and NIST SP 800-41 Rev. 1. Investigate only firewalls you're authorised to manage; rule changes go through your change process. Ends with a supervisor-graded rule review.
- Level
- Intermediate
- Length
- About 100 minutes
- Contents
- 5 lessons · final exam
- Status
- Published · updated 10 Oct 2026
Skills you'll practise
- Identify which rule set evaluates a connection from its ingress interface, direction and NAT
- Predict which rule matches a connection under first-match (quick) and last-match evaluation and the default deny
- Use firewall logs, rule tracker IDs, state tables and vendor tools to confirm which rule passed or blocked a connection
- Distinguish a firewall block from causes that only look like one: traffic that never reaches the firewall, existing states, asymmetric routing and rule-loading failures
- Write a rule-review finding that names the blocking rule, the evidence and the smallest proposed change
Course outline
- 1.Identify which rule set evaluates a connection: ingress interface, direction and NATLesson · 16 min
- 2.Predict which rule matches: first match, last match and the default denyLesson · 16 min
- 3.Use logs, tracker IDs, state tables and vendor tools to confirm which rule matchedLesson · 17 min
- 4.Distinguish a firewall block from causes that only look like oneLesson · 14 min
- 5.Write a rule-review finding that names the blocking rule, the evidence and the smallest changeLesson · 14 min
- 6.Firewall rule review: finding the rule that blocks traffic: knowledge checkKnowledge check · 14 questions
- 7.Firewall rule review: finding the rule that blocks traffic: practical exerciseKnowledge check · 1 question
- 8.Final exam10 questions · passing it completes the course, so people who already know the material can test out
Sources it draws on
The lessons and questions are written from these references, so learners can go back to the original.
- NIST SP 800-41 Rev. 1: Guidelines on Firewalls and Firewall Policy (deny by default, specific rulesets, comments, review and testing)
- Netgate pfSense documentation: Troubleshooting Firewall Rules
- Netgate pfSense documentation: Rule Methodology (inbound per-interface filtering, floating/group/interface order)
- Netgate pfSense documentation: Ordering of NAT and Firewall Processing
- Netgate pfSense documentation: Viewing the Firewall Log (tracker ID, matched rule, reason)
- Netgate pfSense documentation: Floating Rules (quick and last-match behaviour)
- Netgate pfSense documentation: Port Forwards (filter rule association)
- OPNsense documentation: Firewall rules (processing order, quick, Inspect)
- OPNsense documentation: Firewall log files (Live View, rid field)
- Fortinet FortiOS 7.6 Administration Guide: Firewall policy (policy parameters, sequence views, Policy match)
- Fortinet FortiOS 7.6 Administration Guide: Debugging the packet flow
See it with your own jobs and topics
Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.