Firewall selection
FortiGate, Sophos, pfSense or OPNsense compared on user count, throughput, VPN needs and budget, with a recommended model.
Start here
Free Audits 5Urgent help
Emergency 4Ongoing support
Managed IT 5Projects
Servers & Hosting 6 Network & Virtualization 9 DevOps 5 Security & Recovery 5 Hardware & Licensing 2Find out where your servers, security, backups and performance stand, at no cost.
Server down, network out, site hacked or data lost? Call us now.
Monthly network and server support with response times written into the contract.
Setup, configuration, management and migration of Linux and Windows servers, panels and mail.
Network design and cabling, MikroTik, VoIP, branch links, virtualization and private cloud.
Networking & communications
Virtualization & cloud
Containers, Kubernetes, automated delivery, infrastructure as code and observability.
Server hardening, firewalls, backup and DR, ransomware recovery and incident forensics.
Advice, supply and installation of servers and network gear, plus genuine enterprise licenses.
Start here
Urgent help
Ongoing support
Projects
A firewall installed years ago with a pile of any-any rules looks like protection and does very little. We choose and install the right firewall or audit the one you have, document every rule, and segment the network so one infected machine can't reach everything else.
Network security services cover choosing, installing or auditing a company firewall, writing documented rules that allow only needed traffic, and segmenting the network so one infected machine can't reach everything else. They are needed when a firewall installed years ago is full of any-any rules, cameras, servers and staff PCs share one network, or remote staff connections may not be secure. PikoSystem compares FortiGate, Sophos, pfSense and OPNsense on user count, throughput and budget, defines zones, VLANs and least-privilege rules, enables IPS and web filtering where they add value, finds duplicate rules and exposed management ports, and sets up SSL VPN or IPsec with Active Directory login. Changes go in during an agreed window. You receive a configuration backup, a rule table with a reason and owner for each rule, a zone and VLAN map and an audit report.
FortiGate, Sophos, pfSense or OPNsense compared on user count, throughput, VPN needs and budget, with a recommended model.
Zones and VLANs, least-privilege rules and NAT, with IPS, web filtering and application control enabled where they add value.
Duplicate, unused and overly permissive rules found, firmware version checked, and management ports exposed to the internet closed.
SSL VPN or IPsec with Active Directory authentication and, where possible, two-factor login.
Firewall logs sent to Syslog or FortiAnalyzer, with periodic reports on blocked traffic and usage.
Centrally managed business antivirus such as ESET or Kaspersky deployed to clients and servers.
Firewall datasheets list several throughput figures, and the big headline number usually covers plain packet forwarding. Once IPS, antivirus and application control are on, the relevant figure is threat protection throughput, which is far lower, and SSL inspection throughput is lower again. Choosing a model on the headline number is the most common reason the internet feels slow after a new firewall goes in.
Other factors: concurrent VPN users, whether you need an HA pair, the number of branches and tunnels, the length and tier of the security subscription, and whether an old firewall full of rules is being replaced.
HTTPS or SSH management left open on the WAN interface still turns up regularly. Serious FortiOS SSL VPN flaws such as CVE-2018-13379 and CVE-2022-42475 did the most damage on devices whose firmware had gone months without updates. Management should only be reachable from the internal network or VPN, restricted with trusted hosts.
Other repeat findings: SSL VPN without two-factor login, the default admin account with an old password, an any rule near the top that makes everything below it irrelevant, no logging on denied traffic, and configuration backups that exist only on the device or on a former admin's laptop.
Most web traffic is encrypted, so without SSL inspection a firewall's IPS and antivirus see very little of it. Deep inspection decrypts and re-encrypts traffic, which requires the firewall's CA certificate on every client; in a domain that is pushed through Group Policy.
The costs are real. It uses a lot of CPU, banking sites and apps with certificate pinning must be exempted, and you need a clear policy on staff privacy. For many companies, certificate inspection, which only checks the domain name, combined with web filtering is the better balance.
A firewall controls traffic between zones and can do nothing inside a single VLAN. If an internal server is weak, a user in the same zone can still reach it, which is why server hardening and host firewalls belong alongside the network firewall.
VLANs have to be defined correctly on the switches as well, with unused ports shut. Firewall logs become useful when they are read next to server logs in a central system such as Wazuh or ELK. Branch IPsec tunnels on the same firewall are best designed together with the rule base.
We review your equipment, network layout, internet-facing services and current rules.
We go through the proposed segmentation and rules with you so nothing your business needs gets blocked.
Changes go in during an agreed window, with the previous configuration ready to restore.
You get the documentation, and over the following days we watch the logs for legitimate traffic that was blocked.
Both suit small and mid-sized businesses. The choice usually comes down to license and support availability, your team's familiarity, and whether you need features like SD-WAN. On a tight budget, pfSense is also a dependable option.
It depends on the number of sites, VLANs and rules. A simple office is a short job, while replacing an old firewall with many rules needs more planning. We give you a firm schedule after the site review.
For small offices, a MikroTik router with well-written rules can serve as a network-layer firewall. It lacks the IPS, web filtering and application control of a UTM appliance. If you need those, we recommend a dedicated firewall.
Related searches
Quote
A few lines on where things stand and what you want is enough. An engineer calls you back, not a sales rep.