Four Firewall Mistakes Still Wrecking Networks in 2026
Find Threat Talks on
Three out of four firewall rule sets ON2IT’s SOC inherits share the same blind spots, and none of the fixes cost extra licensing.
Jelle Konings, security optimization specialist at ON2IT, joins host Lieuwe Jan Koning, Co-founder & CTO at ON2IT, to walk through the firewall misconfigurations his team finds on nearly every network it takes over: missing logging, no identity tied to traffic, no default deny rule, and port-based policies doing an application’s job. Get this wrong, and an attacker needs nothing more than a consumer VPN app to walk data out the door unnoticed.
What you’ll learn
- The free fix most firewalls skip. Logging and inspection are often already licensed, just never turned on.
- Why an IP address isn’t a user. User-ID ties traffic to an identity and a group before a connection is trusted.
- The rule that should always come last. Without a default deny, vendor defaults can quietly allow traffic nobody approved.
Your cybersecurity experts
Episode details
An inherited firewall rarely reflects a decision. It reflects an accumulation: a rule added for a project, an exception that never expired, a vendor default nobody revisited. Jelle Konings’ four mistakes are less a checklist than a map of where that accumulation always happens first.
The identity gap matters most for what it removes from the attacker’s side of the equation. Once a firewall can enforce policy against a user and a group, not just an IP address, the perimeter stops being a location and starts being a decision made on every packet. That is the same shift Zero Trust asks for at the network layer specifically.
Default deny is the philosophical center of the episode, even though it arrives as the third item on Jelle’s list. Every allow rule is a decision. Every rule base without an explicit deny at the bottom is a rule base making decisions by accident, via whatever the vendor shipped as a fallback.
The application-identification mistake is the one with the clearest cost: a policy scoped to a port, not an application, hands an attacker (or an average employee with a commercial VPN app) a route off the network that never has to touch a rule written to stop it. ON2IT’s SOC typically inherits environments at 30 to 40 percent application-based policy coverage against a 60 to 80 percent target. That gap is where the next incident quietly waits.
Get your Hacker T-shirt
Join the treasure hunt!
Find the code within this episode and receive your own hacker t-shirt for free.





