Skip to content
Next2IT

Is Your Firewall Locked Down on the Way Out?

Most firewalls guard the front door and ignore the back. Our free outbound security test checks your egress filtering in seconds, from your browser.

Next2IT
The Next2IT outbound security test tool, ready to check which outbound ports leave the network unchallenged.

Ask most IT teams about their firewall and they’ll tell you about the inbound rules: what’s blocked, what’s port-forwarded, who can VPN in. Ask what’s allowed out of the network and the answer is often “everything”, usually followed by a thoughtful pause.

That pause is worth listening to. Modern attacks rarely batter the front door. They arrive by email or a compromised website, and then the malware inside your network phones home: to fetch instructions, to pull down more tooling, to push your data out. Every one of those steps is an outbound connection. If your firewall lets anything talk to anywhere on any port, the attacker’s job is substantially easier.

A ten-second check

Our free outbound security test runs from your browser, inside your network, and checks which outbound paths leave your site unchallenged: web traffic on the standard HTTPS port, and connections on the non-standard ports that malware likes precisely because nobody watches them.

Green across the board on the odd ports is what you want to see. If everything comes back open, your firewall is doing half its job.

What good egress control looks like

You don’t need to strangle the business to tighten the way out. The pattern we deploy for clients is straightforward: allow web browsing through inspection, allow the specific ports your applications genuinely need to the places they need them, and block the rest by default. Pair that with DNS filtering and you’ve removed the easy channels an intruder relies on.

It’s also one of the areas Cyber Essentials assessors and cyber insurers increasingly poke at, so a quick win here helps the paperwork as well as the security.

If the test worries you

Run the test, and if the results aren’t what you hoped, don’t panic: most firewalls can do proper egress filtering, they’ve just never been asked to. Tightening the rules is usually a planned afternoon’s work, not a project. We do it as part of our network services, and if your firewall itself is due for retirement, our FortiGate and Palo Alto end-of-life checkers will tell you in seconds. Or just ask us to take a look.

Share

Let's talk IT.

Tell us what you're trying to achieve and we'll map out the right approach. No jargon, no hard sell.

Book a meeting