PikoSystem IT engineering services
Security & Recovery

Firewall installation, management and network security

A firewall installed years ago with a pile of any-any rules looks like protection and does very little. We choose and install the right firewall or audit the one you have, document every rule, and segment the network so one infected machine can't reach everything else.

Tools & technology firewall-network-security
  • FortiGate
  • Sophos Firewall
  • pfSense
  • OPNsense
  • MikroTik
  • FortiAnalyzer
  • ESET PROTECT
  • Kaspersky Security Center
6work areas
4deliverables
4steps

What is Firewall & Network Security?

Network security services cover choosing, installing or auditing a company firewall, writing documented rules that allow only needed traffic, and segmenting the network so one infected machine can't reach everything else. They are needed when a firewall installed years ago is full of any-any rules, cameras, servers and staff PCs share one network, or remote staff connections may not be secure. PikoSystem compares FortiGate, Sophos, pfSense and OPNsense on user count, throughput and budget, defines zones, VLANs and least-privilege rules, enables IPS and web filtering where they add value, finds duplicate rules and exposed management ports, and sets up SSL VPN or IPsec with Active Directory login. Changes go in during an agreed window. You receive a configuration backup, a rule table with a reason and owner for each rule, a zone and VLAN map and an audit report.

When you need Firewall & Network Security

  • We don't know which firewall rules are still needed.
  • The firewall license has expired and security updates have stopped.
  • Cameras, servers and staff computers all sit on the same network.
  • Staff connect from home and we're not sure the connection is secure.

What Firewall & Network Security includes

01

Firewall selection

FortiGate, Sophos, pfSense or OPNsense compared on user count, throughput, VPN needs and budget, with a recommended model.

02

Installation and configuration

Zones and VLANs, least-privilege rules and NAT, with IPS, web filtering and application control enabled where they add value.

03

Firewall audit

Duplicate, unused and overly permissive rules found, firmware version checked, and management ports exposed to the internet closed.

04

Remote access VPN

SSL VPN or IPsec with Active Directory authentication and, where possible, two-factor login.

05

Logging and reporting

Firewall logs sent to Syslog or FortiAnalyzer, with periodic reports on blocked traffic and usage.

06

Network antivirus

Centrally managed business antivirus such as ESET or Kaspersky deployed to clients and servers.

What you get from Firewall & Network Security

  • A configured firewall with a configuration backup
  • A rule table with the reason and owner for every rule
  • A network map showing zones and VLANs
  • An audit report with high-risk findings and the action taken on each

Firewall & Network Security: a practical guide

What drives firewall sizing and cost?

Firewall datasheets list several throughput figures, and the big headline number usually covers plain packet forwarding. Once IPS, antivirus and application control are on, the relevant figure is threat protection throughput, which is far lower, and SSL inspection throughput is lower again. Choosing a model on the headline number is the most common reason the internet feels slow after a new firewall goes in.

Other factors: concurrent VPN users, whether you need an HA pair, the number of branches and tunnels, the length and tier of the security subscription, and whether an old firewall full of rules is being replaced.

FortiGate and Sophos configuration mistakes

HTTPS or SSH management left open on the WAN interface still turns up regularly. Serious FortiOS SSL VPN flaws such as CVE-2018-13379 and CVE-2022-42475 did the most damage on devices whose firmware had gone months without updates. Management should only be reachable from the internal network or VPN, restricted with trusted hosts.

Other repeat findings: SSL VPN without two-factor login, the default admin account with an old password, an any rule near the top that makes everything below it irrelevant, no logging on denied traffic, and configuration backups that exist only on the device or on a former admin's laptop.

SSL inspection: do you need it?

Most web traffic is encrypted, so without SSL inspection a firewall's IPS and antivirus see very little of it. Deep inspection decrypts and re-encrypts traffic, which requires the firewall's CA certificate on every client; in a domain that is pushed through Group Policy.

The costs are real. It uses a lot of CPU, banking sites and apps with certificate pinning must be exempted, and you need a clear policy on staff privacy. For many companies, certificate inspection, which only checks the domain name, combined with web filtering is the better balance.

How the firewall fits with the rest of network security

A firewall controls traffic between zones and can do nothing inside a single VLAN. If an internal server is weak, a user in the same zone can still reach it, which is why server hardening and host firewalls belong alongside the network firewall.

VLANs have to be defined correctly on the switches as well, with unused ports shut. Firewall logs become useful when they are read next to server logs in a central system such as Wazuh or ELK. Branch IPsec tunnels on the same firewall are best designed together with the rule base.

How Firewall & Network Security works

  1. 01

    Site visit and review

    We review your equipment, network layout, internet-facing services and current rules.

  2. 02

    Design

    We go through the proposed segmentation and rules with you so nothing your business needs gets blocked.

  3. 03

    Implementation

    Changes go in during an agreed window, with the previous configuration ready to restore.

  4. 04

    Handover and follow-up

    You get the documentation, and over the following days we watch the logs for legitimate traffic that was blocked.

Firewall & Network Security: frequently asked questions

Should we choose FortiGate or Sophos?

Both suit small and mid-sized businesses. The choice usually comes down to license and support availability, your team's familiarity, and whether you need features like SD-WAN. On a tight budget, pfSense is also a dependable option.

How long does a FortiGate deployment take?

It depends on the number of sites, VLANs and rules. A simple office is a short job, while replacing an old firewall with many rules needs more planning. We give you a firm schedule after the site review.

Is a MikroTik router enough as a firewall?

For small offices, a MikroTik router with well-written rules can serve as a network-layer firewall. It lacks the IPS, web filtering and application control of a UTM appliance. If you need those, we recommend a dedicated firewall.

Related searches

  • network security services
  • firewall installation
  • FortiGate setup
  • Sophos firewall configuration
  • pfSense
  • UTM setup
  • network antivirus

Quote

Tell us what you need, we'll come back with a plan and a price

A few lines on where things stand and what you want is enough. An engineer calls you back, not a sales rep.

  1. 01We read your request and call if anything is unclear.
  2. 02If needed, we do a quick remote review or a site visit.
  3. 03You get a written proposal with scope, timeline and cost.

Your details are only used to answer this request.