Managed security

Firewall Management

Rules someone still understands.

Managed firewall means happier IT owns the configuration, the firmware, the rule set and the logs on the firewalls at the edges of your network: in your building, in a data centre, or delivered from the cloud. The value is not the hardware, which you probably already have. It is that somebody reads the logs, and that the rule added for a project in 2019 eventually gets removed.

Who it's for

Firewalls are configured once and then inherited.

They rarely fail loudly. They drift, a rule here, a deferred firmware update there, until nobody can say with confidence what the current configuration allows.

Nobody knows what half the rules are for. Each was added for a good reason by somebody solving a real problem on a deadline. None were removed, because removing a rule you do not understand feels riskier than leaving it. That instinct is how rule sets grow to four hundred lines.

The firmware is behind. Updating it needs a maintenance window, a window needs planning, and planning needs someone whose job it is. So it waits, and the gap between installed and current quietly widens.

The logs go somewhere nobody looks. Firewalls produce a great deal of useful information about what is leaving your network, which is often more interesting than what is arriving. Unread, it is disk usage.

It was configured by somebody who has moved on. The documentation is a password in a spreadsheet and a memory of a conversation. Not unusual, and worth fixing before the next change rather than during it.

The rule worth looking for today

Open your firewall and search for a rule allowing any source to any destination on any port. Most inherited rule sets have one, usually added to make something work on a Friday afternoon.

Also worth checking: whether the management interface is reachable from the internet, and whether the admin password is still the one from the installation.

What's included

What we take ownership of.

The point of managing a firewall is that changes are deliberate, recorded and reversible. Almost everything below serves that.

  • A documented configuration baseline

    What the device is, what it is configured to do, and why, written down and kept current. This is the deliverable that outlives any particular provider, and it is the one most often missing when we take over an existing firewall.

  • Firmware and patching in a booked window

    Security updates applied on a schedule agreed with you rather than when somebody remembers, with a tested rollback path. Firewalls sit at the edge of your network, so the software running on them matters more than the software on most things.

  • Rule review and removal

    A scheduled read-through of the rule set, tracing each rule to a current reason and removing those that have none. Removals are staged and reversible so nothing breaks silently, and every one is recorded with who approved it.

  • Segmentation between zones

    Servers, staff devices, guest wifi, and anything industrial or building-related kept in separate zones with deliberate routes between them. Most small networks are one open space because nobody ever needed them not to be.

  • Logs into the SOC

    Firewall logs feed a SIEM, a security information and event management system, the central place security logs are gathered and compared, so traffic patterns can be checked against what endpoints and identity are reporting rather than read in isolation.

  • Remote access configuration

    Where the firewall still terminates a VPN, that configuration is ours: who can connect, with what second factor, and to what. Where it makes more sense to move remote access to a cloud service instead, we will say so, that is on the SASE page.

  • Change control with a written record

    Every change requested, approved, made and dated, with the reason. It is unglamorous and it is what makes an audit, an insurance question or an incident investigation take an afternoon instead of a week.

  • A monthly report including what we removed

    Blocked traffic worth knowing about, firmware status, rule changes, and, the line most reports omit, what was taken away. A rule set that only grows is a rule set nobody is managing.

How it works

Document first. Nothing changes in week one.

Taking over an undocumented firewall and immediately tidying it is how a provider causes an outage on their first Monday. We read before we write.

  1. Audit and document

    What hardware you have, what software version it runs, what the rules currently allow, what is reachable from outside, and where the gaps are. The output is a document you own, useful whoever manages the device afterwards.

  2. Harden and schedule

    The clearly safe fixes first: management interfaces closed to the internet, default credentials changed, logging turned on and pointed at us, firmware brought current in a booked window. Then a maintenance schedule you know about in advance.

  3. Monitor, review, remove

    Logs flow into our security operations centre. Rules are reviewed on a cycle, and the ones without a current reason are staged for removal and then removed. You get a monthly report and a change record you can hand to an auditor.

What it costs

Per firewall, per month, plus a one-off audit.

Priced on devices and sites rather than on the number of rules, because pricing on rules would make us reluctant to remove any.

Multiple sites are priced per device rather than as a bundle, because the work genuinely is per device.

We will not quote ongoing management of a device we have not read.

Hardware is separate and quoted only when it is genuinely needed, a device out of vendor support, or one without the capacity for what you now run through it. Vendors we support: Cisco Meraki. For happier IT managed IT clients, firewall management is inside the agreement rather than a separate line.

We will manage the one you have

A proposal that opens with replacing hardware you bought three years ago deserves a question about why. Most firewalls in organizations of this size are capable and badly configured rather than inadequate.

The exceptions are real and we will name them: a device past vendor end-of-support receiving no security updates, or one being asked to inspect far more traffic than it was sized for.

Why us for this

The work is removal, and removal takes nerve.

Adding a firewall rule is easy and safe. Removing one is neither, because the person removing it is the person who breaks something if they are wrong. So rules accumulate, and after a few years the configuration allows considerably more than anybody intends, not through carelessness, but because nobody had a mandate to take anything away.

Managing a firewall properly means having that mandate and a method: trace each rule to a current reason, stage removals, watch what happens, keep the rollback ready. It is slow, and it is the part that actually reduces what your network exposes. The monthly report says what we removed for exactly that reason.

Underneath it, the logs feed our own security operations centre in Canada, staffed by happier IT employees, so a device behaving oddly at the endpoint layer can be checked against where it has actually been connecting. Staffed hours: 24/7, with the Surrey office on Monday to Friday, 8:00 am to 5:00 pm Pacific.

Go deeper

Questions

What people ask before they sign anything.

What is managed firewall service?

It means a provider takes ownership of your firewall’s configuration, firmware, rule set and logs, under an agreed change process. You still own the hardware. What changes is that updates happen on a schedule, changes are recorded, rules are reviewed and removed when they are no longer needed, and somebody reads what the device reports. Most firewalls are competent products that nobody has had time to look after.

Do we still need a firewall if we move to SASE?

If there is equipment in your building, servers, printers, cameras, machinery, guest wifi, then yes. SASE changes how people reach applications from wherever they are working. It does not remove the need for something governing traffic at a site with things plugged into it. The common pattern is SASE for people and cloud access, with a managed firewall continuing at the sites that still have equipment.

Can you manage the firewall we already own?

Usually, and that is our preference. We start with an audit: what it is, what version it runs, what the rules currently allow, whether it is still receiving security updates from the vendor. If it is supported and appropriately sized, we manage it. If it is past end-of-support or badly undersized for what you now run through it, we will say so plainly and quote the alternative alongside.

How often should firewall rules be reviewed?

A full review at least annually, plus a review of anything added since at each quarterly meeting. The reason is not compliance, though it satisfies most frameworks. It is that rule sets only grow otherwise, and after a few years the configuration permits more than anybody intends. The specific thing to look for is any rule allowing all traffic from anywhere, which almost every inherited configuration contains.

Does this include intrusion prevention?

Where your firewall has the capability and the licence, yes, configured, tuned and monitored rather than switched on and forgotten. Intrusion prevention inspects traffic for known attack patterns and blocks them. It is worth having, and it is not a substitute for the endpoint and identity layers, because a great deal of traffic is encrypted and much of what matters now happens through a legitimate login rather than across the network perimeter.

How do emergency firmware updates work?

When a vendor publishes a fix for something being actively used against devices like yours, it goes outside the normal schedule. We tell you what it is, what the update requires in terms of downtime, and when we propose to do it. For happier IT managed IT clients that is generally an authority you have already given us; standalone, it is a call. Either way, you get a written record afterwards.

What does managed firewall cost?

When comparing quotes, ask whether firmware updates and rule reviews are included or billed as changes, that distinction is where the real difference sits.

Want to know what this would look like for you?

A 30-minute call. No slides, no audit fee, no obligation. We ask what is breaking and tell you honestly whether we are the right fit.