
A few weeks ago, I was asked by a GRC consultant a simple question:
Is our East-West traffic truly controlled—or are we just assuming it is?
On paper, everything looked correct. ACI was enforcing policy, PBR was redirecting traffic to the firewall, and FortiGate VDOMs were segmenting environments. But I wanted proof—not assumptions.
So I built an end-to-end validation model:
ACI Fabric → PBR → Firewall → Policy Intelligence → GRC Evidence
To make this repeatable and evidence-driven, I developed an automated pipeline that correlates firewall policies with live runtime traffic across all VDOMs. This shifted the approach from static configuration review to continuous validation.
The findings were clear:
✔ Enforcement exists
✔ Traffic is inspected
❗ But policy precision needs refinement
A small number of active policies allow broader-than-intended access—particularly toward identity and infrastructure services like AD, DNS, and PKI.
Most importantly, these are not theoretical risks—they are validated by real session data.
This transformed the conversation:
From “Do we have firewall rules?”
To “Are those rules aligned with least privilege?”
Today, I don’t just see the network—I understand how it behaves.
I turned firewall configuration into governance intelligence.
The real risk isn’t missing controls—it’s believing they’re already working.
-Mohammad Iqbal
Leave a Reply