A firewall sits on nearly every business network with an internet connection. A box that's switched on doesn't protect you by itself. Weak rules leave openings attackers can use.
What the firewall is doing
A firewall sits between your internal network and the internet and controls what is allowed through. It examines every packet, applies the rules you have defined, and records each allow or block.
Business models sold today (often called next-generation firewalls, or NGFW) add further checks. They can:
- Inspect encrypted traffic using SSL/TLS inspection
- Identify applications even when they avoid their usual ports
- Block malicious websites and command-and-control domains
- Detect and prevent intrusions through an IPS
- Filter web content by category
The rules that matter
1. Default deny
Begin with a rule that refuses all traffic, then permit only the connections the business needs. That is the reverse of most consumer routers, which allow everything and then try to stop named threats. Default deny is the stronger position.
2. Change default credentials
Every appliance ships with a factory admin username and password. Leave those in place and anyone familiar with the model can reach the admin screen. This still appears often in security audits.
3. Disable unused services
If you're not using the built-in VPN, web server or SNMP, switch it off. Every service left running is another route an attacker can try.
4. Segment your network
Do not place every device on one shared network. At a minimum, separate:
- Staff devices (corporate VLAN)
- Guest Wi-Fi (isolated, internet only)
- Servers (restricted access)
- IoT devices (CCTV, printers and smart hardware on their own VLAN)
A compromised guest device then cannot reach the servers.
5. Keep firmware updated
Vendors release patches for known weaknesses on a regular cycle. Firmware that is never updated leaves those weaknesses open. Set a monthly schedule to check for updates and apply them.
6. Enable logging and review it
Logs show blocked connection attempts, odd traffic patterns and rule breaches. If nobody reads them, those warnings are wasted.
7. Use geo-blocking
If the business only works with clients and partners in the UK and Europe, refuse inbound traffic from countries you have no relationship with. That step cuts out a large share of automated attacks.
8. Enable IPS and threat feeds
Switch on the intrusion prevention system and connect a threat intelligence feed. Known malicious IP addresses and domains are then blocked without a manual update each time.
When a firewall needs replacing
A unit older than five years is often out of support and missing controls that current threats require. Budget for a replacement every four to five years.
For an office of 20 to 50 people, a business-grade firewall from Fortinet, SonicWall or WatchGuard typically costs £500 to £2,000 for the hardware, plus £300 to £800 a year for the security subscription.
Firewall logs and predictive monitoring
Firewall logs and threat feeds produce a steady stream of signals. Predictive monitoring can flag emerging problems in that stream before they spread across the network. It belongs with the rest of the cybersecurity work: rules, firmware and segmentation kept in order.
How Wanzo runs firewalls
We're responsible for the appliance and the rule set, and we keep watching both. Firewalls are specified, installed and run as part of managed IT and network infrastructure. Firmware is patched on a schedule. Rule reviews form part of the monthly service, and threat signals in the logs are checked as they appear.
Next step
If you want this applied to your network and kept current, get in touch. Describe the current setup and we'll set out what needs to change.