> ## Documentation Index
> Fetch the complete documentation index at: https://docs.onefirewall.com/llms.txt
> Use this file to discover all available pages before exploring further.

# What Your Firewall Actually Lets Through

> A gap analysis showing the traffic an existing firewall denies versus what quietly passes through it

<img style={{ borderRadius: '0.5rem' }} src="https://mintcdn.com/onefirewall/mGgHxMsQTm71_QZa/images/case4.png?fit=max&auto=format&n=mGgHxMsQTm71_QZa&q=85&s=79b93c9033f97a3556faa8e0501ac298" width="776" height="621" data-path="images/case4.png" />

This chart comes from a Proof of Value run against an organization's edge, referred to here as Demo Org. The outer ring is a split between traffic the organization's own firewall passed (green) and traffic it denied (red). The inner ring breaks the denied traffic down by severity.

***

## Denied traffic is not automatically the right traffic

Demo Org's existing rule set — geo-blocks, rate limits, static lists — was already stopping a measurable volume of traffic before OneFirewall was introduced. "Denied" and "denied because it was dangerous" are separate claims, however. The inner ring color-codes the denied segment by severity, and the callout marked **Affected Traffic**, pointing at **491** and **256** events, marks the boundary between what the existing rules caught and what fell just outside that boundary.

## Where the discrepancy originates

A gap analysis compares total volume blocked against volume that should have been blocked based on current scoring. A rule set built on static entries doesn't have visibility into an indicator that nineteen independent Alliance members scored Critical an hour earlier — it only enforces what was configured into it at some earlier point. The affected traffic segment in this chart represents that lag: scored, corroborated activity the existing perimeter had no mechanism to recognize at enforcement time.

## Baseline before change

This chart is typically the first output in an engagement because it establishes a baseline using traffic the organization already logs, without requiring a change to existing firewall configuration. It quantifies what current rules catch and what they don't, using the same data source the organization already has.

***

Proof of Value engagements produce this same breakdown against a client's own firewall logs. [Start a Proof of Value](https://onefirewall.com/proof-of-value).
