skip to content

How long must you watch a plant boundary firewall's rule counters before deleting, and what does waiting leave open?

level: seniorimportance: should knowfreq 48%

answer

  1. set the window from the plant calendar
  2. once a year, not once a month
  3. uptime and failover bound the claim
  4. the wait is exposure you are choosing
  5. topology evidence skips the wait

basics

~20 s

Long enough to span the rarest legitimate flow, which at a plant is annual — the shutdown maintenance window, a vendor commissioning visit, a yearly test. Meanwhile every unproven permit stays enforced, so watch selectively rather than uniformly.

solid answer

~60 s

The window has to be set by the business calendar, not by convenience. A manufacturing plant's rarest real flows fire once a year: the shutdown or turnaround maintenance window, a machine vendor dialling in to commission a line, an annual regulatory test, a year-end run. A busy month at full production proves nothing about those, so the honest window is a full cycle including the next occurrence of each known-rare event — and it is only as long as the counter epoch, so device uptime and the last cluster failover bound your claim. The price is that everything you cannot yet defend stays in force for that whole cycle, and an intruder arriving in month three inherits it. So do not wait uniformly. Triage by reach: permits crossing inward into the plant get the attention. Take topology evidence where it exists — a destination in a decommissioned range, an empty address group — because it is independent of the window. And get the calendar from the maintenance planner, not the network team.

go deeper

for a junior

Understand that some legitimate traffic happens only once a year, so a rule reading zero over a short review period may still be carrying a real flow.

for a middle

Explain how the observation window has to be derived from the business calendar and how device uptime and failover history cap the period you can honestly claim.

for a senior

Show how you triage by the reach a permit grants rather than sweeping uniformly, and how topology evidence lets you act on the highest-risk rules without waiting a full cycle.

for a principal

Be ready to argue for the residual risk explicitly: what exposure the organisation is accepting during the observation period and who signs for it.

## Why the window is a business question Deleting on counters is an inference: *nothing matched this rule during period W, therefore nothing needs it*. That inference is only as good as the relationship between W and the cadence of the rarest legitimate flow the rule might carry. In an office estate the rarest flows are often monthly. At a manufacturing plant's IT-to-OT boundary they are annual, and this is the fact interviewers are checking you know: - The **shutdown / turnaround maintenance window**, when the line is stopped for days and engineering, vendor and diagnostic tooling that is used at no other time all reaches in at once. - A **machine vendor's commissioning run** — remote support for a new or rebuilt line, which may happen once for that asset and then not again for years. - An **annual test or calibration** required by a regulator or an insurer. - **Year-end or campaign batch processing** that touches historians and reporting systems on a schedule nobody in the network team sees. Against that calendar, a ninety-day observation is not a short window, it is a wrong one. A rule whose flow fires in week 40 will read zero for the whole of a Q1 review no matter how carefully you watch. ## The window is bounded by the counter epoch, not by the calendar Even a year of intent gives you a year of evidence only if the counters were running for that year. Before quoting any period, establish: - device uptime and the date of the last upgrade reboot; - the date of the last cluster failover, and which member's figures you are reading; - whether any policy operation on that platform cleared counters. If the pair failed over in March, your "twelve months" is four. Writing the epoch date next to every counter in the evidence pack is what stops that being discovered by the change board rather than by you. ## What waiting costs The cost is not zero and you should say so before anyone else does. For the whole cycle: | You pay | Who feels it | | --- | --- | | Every unproven permit stays enforced for another year | Whoever gets breached in that year inherits the reach | | The evidence-collection effort continues across a change freeze and a shutdown | The team doing the review | | The unowned-rule list grows as new exceptions are added | The next person to inherit the rulebase | That is the honest trade, and it is the reason a uniform "observe everything for a year, then decide" plan is a bad plan. You are buying certainty about rules that mostly do not matter with exposure on the ones that do. ## Triage instead of a uniform window Sort the base by what the permit would give an intruder, not by how old it is: 1. **Inbound into the plant from the enterprise, broad destination or broad ports.** Highest reach, highest priority, shortest tolerable delay. These deserve effort beyond counters. 2. **Inbound, narrow and specific.** Counter evidence over a full cycle is proportionate. 3. **Intra-zone or outbound-to-known-service.** Lowest reach; a longer window costs little. Within the top bucket, look for evidence that does not depend on the window at all, because it is both faster and far more persuasive: - the destination address sits in a range decommissioned during a re-addressing project and no longer routes; - the address-object group the rule references is empty, or contains only addresses in that dead range; - the destination VLAN was collapsed and no interface carries it; - the service the rule names was replaced by a documented successor with its own permit that does carry hits. Any one of these is a fact about the topology rather than an absence of observation, and a change board treats them completely differently. ## Get the calendar from the people who own it The network team does not know when the plant's rare things happen; the maintenance planner, the shutdown coordinator and the line engineers do. Asking them two questions — *what happens here once a year, and who dials in from outside* — converts a guess about window length into a dated list you can point at. It also produces owners for a handful of rules, which is the outcome you actually want: a claimed rule is better than a deleted one, because it has someone's name on it. ## What a strong answer sounds like Name the annual cadence and why it makes ninety days meaningless. Bound the claim with the counter epoch. State the cost of the wait plainly and use it to justify triage rather than a uniform sweep. Offer the topology evidence as the route that skips the wait for the rules that matter most. And say what you would do with the residual: a dated list of permits you could not clear, each with the reach it grants written in plain language, handed to somebody who can accept it — not left silently in the base for the next inheritor.

  • Your review runs January to March at full production. Why is that the worst possible window?
    Because it is the period during which the rarest legitimate flows are least likely to appear. Shutdown maintenance, vendor commissioning and annual tests happen on their own calendar, usually not during peak production. A busy quarter maximises hits on the rules you were never going to delete and tells you nothing about the ones you were.
  • Which evidence would let you delete a rule without waiting a full cycle?
    Evidence about topology rather than about traffic: the destination address is in a range that was decommissioned and no longer routes, the address group the rule references is empty, the VLAN was collapsed, or the named service was replaced by a documented successor that carries hits itself. These are facts, not absences, so they do not depend on how long you watched.
  • What do you do with the permits you still cannot clear at the end of the cycle?
    Write them up as a dated list, each with the reach it grants stated in plain language — from where, to what, on which ports — and put it in front of someone with the authority to accept that exposure. The goal is to convert invisible decay into an owned, dated risk. Leaving them unlisted in the base hands the same problem to the next inheritor.

saying these in an interview costs you the question

  • Picks 30 or 90 days because it is the reporting cycle
  • Never asks the plant what happens once a year
  • Quotes a year of counters without checking uptime or failover
  • Applies one observation window to every rule regardless of reach
  • Presents waiting as free rather than as chosen exposure

context