Skip to content

Networks & Infrastructure

Firewall & Network Security

We configure business firewalls with per VLAN policies, so each part of the network reaches only what it should. We close device exposure to the internet, replace open ports with controlled remote access, and hand over documentation of the rules in force so you know at any time who reaches what.

Who it is for

  • Businesses with remote users or branch offices
  • Sites where cameras or machinery are exposed to the internet
  • Companies that do not know which rules are currently in force
  • Organisations needing guest and production network separation

When we are NOT the right choice

  • If only hardware purchase is wanted, with no policy design
  • If there is no willingness to close currently open ports
  • If the request is penetration testing, which we do not undertake

PROCESS

The process

Indicative times from signature of the proposal, subject to hardware availability. Every project is shaped to the size and the needs of the client.

  1. 01Exposure inventory

    We record which devices are reachable from the internet, which rules exist, and which remain active without any current purpose.Time: 2-5 working daysDeliverable: Findings report by severity

  2. 02Per VLAN policy design

    We define what each VLAN may reach. Cameras, production, office and guests do not carry the same rights.Time: Alongside the studyDeliverable: Policy matrix per network segment

  3. 03Implementation and remote access

    We apply the rules, replace open ports with VPN, and enable logging so there is a record of what happened.Time: 1-2 days for a typical siteDeliverable: Controlled access by VPN instead of open ports

  4. 04Testing and verification

    We verify that services which should be closed no longer answer from outside, and that the work which must function still functions.Time: During implementationDeliverable: Confirmation that exposure is closed

  5. 05Handover and periodic review

    We hand over rule documentation. Under a support agreement the rules are reviewed periodically, because a firewall left unmaintained fills with exceptions.Time: On completion and periodicallyDeliverable: Rule and access documentation

What is includedWhat is not included
Exposure and existing rule inventoryPenetration testing and offensive assessments
Per VLAN policy designLegal compliance services
Firewall and routing configurationThird party subscription licences
Controlled remote access by VPNWork on third party equipment we are not given access to
Logging and alerting
Documentation of the rules in force

Technology and equipment

  • MikroTik RouterOS
  • Ubiquiti UniFi
  • Omada / TP-Link
  • Bitdefender
  • IPsec / WireGuard VPN
  • VLAN segmentation

From practice

In almost every inventory we find at least one device answering directly on the internet because somebody once needed remote visibility. Usually it is a camera recorder or a production machine, with factory credentials and no firmware updates for years.

Replacing that practice with a VPN does not remove the capability. It makes it controlled: you know who has access, you withdraw it when it is no longer needed, and a record remains of what was done.

Prerequisites

  • Administrative access to the existing equipment
  • A list of services that must remain reachable
  • A work window for the rule change
  • A decision on who gets remote access, and to what

Cost

Initial implementation is quoted as a project with equipment, configuration and labour separated. Ongoing management and periodic rule review sit within the support agreement, charged monthly rather than by the hour.

We do not publish a price list. Every proposal follows a site survey and separates hardware from labour.

What moves the cost

  • Number of network segments and policy complexity
  • Number of users with remote access
  • Whether branch sites must be interconnected
  • Equipment tier and throughput requirements

Frequently asked questions

Is the provider router not enough?

For a business it rarely is. It cannot apply per VLAN policies, keeps no useful logs, and usually does not support controlled remote access. It is the device that makes the circuit work, not the security of your network.

Why not leave the ports we need open?

Because an open port is permanently reachable by anyone. The same outcome is achieved with a VPN, where access is granted to named people and can be withdrawn.

Do you do penetration testing?

No, we do not undertake offensive assessments. What we do is document actual exposure and report findings by severity, with recommended actions and costs.

How often should rules be reviewed?

Periodically, because every new requirement adds exceptions that stay active long after they are needed. Under a support agreement, review is part of the periodic report.

NEXT STEP

Request a network exposure review

We document what is currently reachable from the internet and deliver a findings report ordered by severity.

GET IN TOUCH

Tell us what you need

Four fields. An engineer replies, not a sales desk.

Fields marked * are required.

By sending this form you accept the processing of your details under our Privacy Policy.