- Home
- Services
- Networks & Infrastructure
- Firewall & Network Security
Networks & Infrastructure
Firewall & Network Security
We configure business firewalls with per VLAN policies, so each part of the network reaches only what it should. We close device exposure to the internet, replace open ports with controlled remote access, and hand over documentation of the rules in force so you know at any time who reaches what.
Who it is for
- Businesses with remote users or branch offices
- Sites where cameras or machinery are exposed to the internet
- Companies that do not know which rules are currently in force
- Organisations needing guest and production network separation
When we are NOT the right choice
- If only hardware purchase is wanted, with no policy design
- If there is no willingness to close currently open ports
- If the request is penetration testing, which we do not undertake
PROCESS
The process
Indicative times from signature of the proposal, subject to hardware availability. Every project is shaped to the size and the needs of the client.
01Exposure inventory
We record which devices are reachable from the internet, which rules exist, and which remain active without any current purpose.Time: 2-5 working daysDeliverable: Findings report by severity
02Per VLAN policy design
We define what each VLAN may reach. Cameras, production, office and guests do not carry the same rights.Time: Alongside the studyDeliverable: Policy matrix per network segment
03Implementation and remote access
We apply the rules, replace open ports with VPN, and enable logging so there is a record of what happened.Time: 1-2 days for a typical siteDeliverable: Controlled access by VPN instead of open ports
04Testing and verification
We verify that services which should be closed no longer answer from outside, and that the work which must function still functions.Time: During implementationDeliverable: Confirmation that exposure is closed
05Handover and periodic review
We hand over rule documentation. Under a support agreement the rules are reviewed periodically, because a firewall left unmaintained fills with exceptions.Time: On completion and periodicallyDeliverable: Rule and access documentation
| What is included | What is not included |
|---|---|
| Exposure and existing rule inventory | Penetration testing and offensive assessments |
| Per VLAN policy design | Legal compliance services |
| Firewall and routing configuration | Third party subscription licences |
| Controlled remote access by VPN | Work on third party equipment we are not given access to |
| Logging and alerting | |
| Documentation of the rules in force |
Technology and equipment
- MikroTik RouterOS
- Ubiquiti UniFi
- Omada / TP-Link
- Bitdefender
- IPsec / WireGuard VPN
- VLAN segmentation
From practice
In almost every inventory we find at least one device answering directly on the internet because somebody once needed remote visibility. Usually it is a camera recorder or a production machine, with factory credentials and no firmware updates for years.
Replacing that practice with a VPN does not remove the capability. It makes it controlled: you know who has access, you withdraw it when it is no longer needed, and a record remains of what was done.
Prerequisites
- Administrative access to the existing equipment
- A list of services that must remain reachable
- A work window for the rule change
- A decision on who gets remote access, and to what
Cost
Initial implementation is quoted as a project with equipment, configuration and labour separated. Ongoing management and periodic rule review sit within the support agreement, charged monthly rather than by the hour.
We do not publish a price list. Every proposal follows a site survey and separates hardware from labour.
What moves the cost
- Number of network segments and policy complexity
- Number of users with remote access
- Whether branch sites must be interconnected
- Equipment tier and throughput requirements
Frequently asked questions
Is the provider router not enough?
Why not leave the ports we need open?
Do you do penetration testing?
How often should rules be reviewed?
NEXT STEP
Request a network exposure review
We document what is currently reachable from the internet and deliver a findings report ordered by severity.
GET IN TOUCH
Tell us what you need
Four fields. An engineer replies, not a sales desk.