A legacy firewall rule base tells you a lot about a network, just rarely what you hoped. Hundreds of entries, any-rules, management exceptions, DMZ shortcuts: each one a record of where the zone model eroded in practice. The temptation is to start deleting. In a hybrid IT/OT environment, that is how you cause the outage.
Why deleting rules is not enough
Firewall rule cleanup in an IT/OT environment is not a cosmetic exercise. Legacy permits, any-rules, management exceptions, DMZ shortcuts and unclear object groups are direct indicators of where segmentation has eroded, but just deleting them risks taking production down, because many of those rules quietly carry a real operational need.
The work is to trace each rule back to a zone, a legitimate flow and an operational owner. Two principles run through it:
Understand first, then reduce
Policy hits, object references and zone context decide what goes, not a guess about what looks unused.
Hybrid, not siloed
The IT, DMZ, admin and OT paths are reviewed together, in one picture, not split by team.
01Extract the configuration
The first step reads the existing setup: interfaces, zones, policies, objects and the obvious gaps. A configuration file is parsed automatically; the result is not a target design yet, but a reliable fact base that puts IT, OT and security on the same page.
- Zones, interfaces and unzoned boundaries become visible
- Broad objects and management exceptions surface as structural issues
- Inventory knowledge comes from the live config, not PDFs and change tickets
02Prioritise the findings
Not every legacy issue is equally critical. Any-rules, broad management permits, missing inspection and hard IT/OT exceptions are ranked by risk and feasibility, so the cleanup starts where it matters, not where it is easiest. The panel below is the parser output from the imported configuration: 33 findings across policy, hardening, VPN and architecture.
03Derive the target communication
Cleanup without a target design just grows new exceptions. From the zone model and the communication matrix, a reduced target rule set emerges, and conduits document the permitted boundaries between IT, DMZ and OT, with everything else denied by default.
- Define IT, DMZ and OT boundaries as explicit conduits
- Restrict admin access to jump hosts, session controls and approved targets
- The communication matrix becomes the authoritative reference for the new rule set
That principle has to become something a team can actually review and sign off. The communication matrix turns it into an explicit grid: every pair of zones gets a deliberate Allow or Deny decision, with protocol-specific exceptions where a flow is genuinely needed. It is the document the new rule set is built from, and the reference an auditor can check it against.
From analysis to implementation
The analysis delivers the fact base and the prioritisation. Four building blocks then carry the target design into a running rule set:
1
Align matrix and target zones
The analysis becomes an approvable target design: zones, conduits and documented target flows for IT, DMZ, admin and OT.
2
Plan pilot rules in waves
Instead of a risky big bang, high-impact rules are bundled into pilot packages, each with a maintenance window and a fallback path.
3
Decommission legacy rules
Legacy exceptions, broad objects and unresolved permits are not blindly deleted but cleanly migrated or deliberately removed.
4
Anchor review and ownership
Logging, responsibilities and recurring reviews keep the new rule set from eroding again the moment the project ends.
What good cleanup looks like
Beyond delete candidates
Management access, DMZ boundaries and OT services are reviewed too, not just the obviously dead rules.
Rules tied back to zones
Every rule is verified against a target design of zones and conduits, not left as a standalone permit.
Inventory stays visible
Legacy exceptions and hybrid paths are deliberately migrated or decommissioned, never quietly ignored.
Review-ready operations
Logging, ownership and regular reviews stop the rule base from growing uncontrolled all over again.