This document is a checklist designed for auditing firewalls. It aims to provide a generic listing of security considerations relevant to firewall auditing, excluding vendor-specific security aspects. The checklist emphasizes the importance of evaluating technical security elements rather than manual protections. Key considerations include assessing the operating system security, identifying and mitigating threats from internal modems, and ensuring the security of application-level firewalls. The checklist outlines best practices for rulesets, including anti-spoofing filters and management permit rules, and advises on monitoring and logging to detect potential security violations. It also highlights the need for regular updates and patches to firewall software, as well as the importance of maintaining a secure network architecture, such as using a demilitarized zone (DMZ). The document concludes with specific recommendations for blocking certain ports and addresses to enhance firewall security.