HomeServicesManaged Firewall Services

Managed Firewall Services: Rules, Updates and 24/7 Monitoring

A managed firewall service is ongoing care of your business firewall by an outside engineering team: rule changes under change control, firmware and security updates, 24/7 monitoring with an engineer acting on the alerts, and VPN and failover settings that keep working. NetSys runs that service on Cisco Meraki and Fortinet firewalls, and on other supported business firewalls after a check of the model, firmware and vendor support.

See Network Security Services
By The NetSys Group · Published · Editorial policy

The short answer

Managed firewall services cover the work a firewall needs after it is installed, which is most of its life: reviewing rules, approving changes, applying firmware and security updates, managing VPN accounts, testing failover, keeping logs and acting on alerts. NetSys includes this in every managed IT agreement and offers it on its own to businesses with in-house IT. Hardware and the vendor's security subscriptions are separate lines, and we publish no rate card.

Closest related page: Network security and firewall management. That page covers the wider network security program, from segmentation to remote-access policy; this one covers the firewall itself: what managing it involves, what is included and what moves the price.

Why a firewall needs an owner

A firewall gets configured once and then changed for years. Every new vendor connection and remote worker adds a rule, few rules are ever removed, and the firmware falls behind because updating it takes the office offline for a few minutes. Eventually the device still works every morning but no longer matches the business, while its VPN portal faces the internet with nobody reading the log.

NIST's firewall guidance, SP 800-41, describes the routine most small offices skip: rule changes handled through formal change control, periodic rule reviews, patches applied as vendors release them, regular configuration backups and logs monitored continuously. A managed firewall service is that routine with a name on it, whether there is one firewall in one office or one at every location, joined over site-to-site VPN.

The routine behind a managed firewall

Rule changes come from the named contacts in your agreement, get tested, and are recorded with the reason and a way back. Firmware follows the vendor's advisories: Fortinet publishes its security advisories on the second Tuesday of each month, and a fix for a flaw on CISA's Known Exploited Vulnerabilities list moves ahead of the queue. Updates are installed in your agreed maintenance window, after a configuration backup. The firewall reports into the same 24/7 monitoring as your computers and servers, and an engineer who knows your network picks up the alerts. Each month you get a short summary of the firmware level, what changed and what needs a decision from you.

What managed firewall services include

Configuration and rule reviews

Every rule gets an owner and a reason, or it comes out.

  • The rule base exported and read line by line at onboarding, with unused, duplicate and overly broad rules flagged
  • Each material rule recorded with its purpose, who asked for it and when it is next reviewed
  • Periodic reviews of every change since the last review, as NIST SP 800-41 recommends
  • Admin access limited to named accounts with MFA where the platform supports it, and the management page kept off the internet

Firmware and security updates

Vendor fixes in your maintenance window, urgent ones sooner.

  • Vendor advisories tracked against your exact model and firmware, with subscription and support renewal dates alongside
  • Updates installed in the window agreed with you, after a configuration backup
  • Fixes for flaws on CISA's Known Exploited Vulnerabilities list handled out of cycle
  • Release notes read before every upgrade, since a new version can remove or change a feature you rely on

24/7 monitoring and alert response

Monitoring raises the alert; an engineer decides what happens next.

  • The firewall reporting into the same 24/7 monitoring as your computers and servers, through NinjaOne
  • Alerts on the events NIST SP 800-41 lists, such as rule changes, reboots and failover, plus repeated failed VPN logins
  • Severe alerts follow the escalation path in your agreement at any hour; routine ones wait for staffed help desk hours
  • Actions we may take before calling you, such as disabling a compromised VPN account, agreed in writing in advance

Change control

No change without a request, a test and a way back.

  • Changes requested by the contacts named in your agreement, not by whoever happens to call
  • Each change recorded with what it does, who approved it and how to reverse it
  • Configuration backed up before the change and checked from a user's side afterward
  • The platform's own audit trail kept as evidence, such as the change log in the Cisco Meraki dashboard

High availability and ISP failover

A second internet line, and a second firewall where downtime costs more than the unit.

  • A backup internet line or cellular failover configured on the firewall and kept current
  • Warm-spare pairs on Cisco Meraki MX, or active-passive clusters on FortiGate, where the business cannot wait for a replacement unit
  • Failover tested in an approved window by pulling the primary line and checking what keeps working
  • Circuit IDs and carrier contacts recorded, so a line fault reaches the carrier quickly

VPN and remote access

Remote access that checks who is connecting.

  • Site-to-site VPN between offices, and remote-access VPN for staff who need the office network
  • VPN sign-in through Microsoft Entra ID with MFA where the platform supports it, as Cisco Secure Client does on Meraki MX
  • Named VPN accounts only, removed the day someone leaves, with vendor access given an end date
  • FortiGate remote access moved off SSL VPN tunnel mode before any upgrade to FortiOS 7.6.3 or later, where tunnel mode no longer exists

Logging and reporting

Logs kept off the box, and a report written for an owner.

  • Logs kept on the firewall and copied to central storage, as NIST SP 800-41 advises
  • A monthly summary of firmware level, updates applied, changes made and decisions waiting on you
  • Change records and update history ready for a cyber insurance questionnaire or an audit
  • Longer retention and correlation with identity logs through SOC monitoring, where a framework calls for it
Why NetSys

Why businesses hand their firewall to NetSys

Tell us the firewall make and model, how many offices and remote users depend on it, and who changes the rules today. A NetSys engineer, not a salesperson, will tell you what onboarding would check first and what the monthly service would cover. Call 845-203-3914 or request a call.

Who does the work: meet the NetSys team on our About page.

  • Firewall, switching, Wi-Fi and failover designed on Cisco Meraki or Fortinet, the platforms our engineers build on
  • Monitoring that runs 24/7, with severe alerts escalated at any hour to engineers who already know your network
  • Every rule change recorded with an owner, an approval and a way to reverse it
  • Firmware and security subscriptions kept current as part of the agreement
  • The firewall, your computers, Microsoft 365 and the backups under one agreement, so an alert never falls between two vendors
  • Running business networks since 1998, from one office in Brooklyn, on month-to-month agreements
From our client work

Managed Firewall Services in practice

Client names are withheld. Each card is the scope of a real NetSys engagement, as delivered.

What is included, and what is project work

The monthly service covers running the firewall you have. Work with a start and an end, and anything the vendor charges for, is scoped separately so it can be planned and approved:

AreaIncluded in the monthly serviceScoped or billed separately
Rules and configurationRule reviews, approved rule changes, configuration backups and control of admin accountsA network redesign or a new segmentation plan
UpdatesFirmware and security updates in the agreed window, urgent fixes out of cycle, renewal dates trackedThe vendor's security subscriptions and support contracts themselves
Monitoring24/7 monitoring of the firewall, with engineers acting on alertsIncident investigation beyond the agreed scope, which our incident response service covers
Remote accessVPN accounts added and removed, and MFA on VPN sign-in where the platform supports itReplacing the VPN with zero trust network access
ResilienceFailover settings kept current and tested in an approved windowA second firewall or a backup internet line, bought and installed
HardwareVendor support cases and replacement coordination when a unit failsNew or replacement firewall hardware, and installing it

Firewall management sits inside every NetSys managed IT agreement and is available on its own for businesses with in-house IT. Coverage hours, escalation contacts and the actions we may take before calling you are written into the agreement.

How onboarding works

Taking over a firewall follows the same order every time, whether it protects one office or several:

  • Access: we get admin access through a named account and record the model, serial number, firmware version, support contract and subscription dates.
  • Backup: the current configuration is exported and stored before anything changes, so every later step has a way back.
  • Baseline review: an engineer reads the rule base, the VPN and admin accounts and the failover settings, and checks whether the management page answers from the internet.
  • Quick fixes: former staff accounts, shared logins and rules nobody can explain are removed or restricted, each approved with you first.
  • Monitoring: the firewall joins 24/7 monitoring, and the after-hours contacts and pre-approved actions are agreed in writing.
  • Firmware: the firewall is brought to a supported release in an agreed window, after any feature changes the release notes call for.
  • Handover: you get a written summary of what we found and changed, which rules still need an owner and which hardware or subscriptions are near the end of support.

Timing depends on the number of firewalls and sites and on how quickly the current provider hands over admin access, so target dates go in the proposal.

Cisco Meraki and Fortinet: what differs by platform

The routine is the same on both platforms we design on; the mechanics differ. Checked against Cisco Meraki and Fortinet documentation in October 2026:

TaskCisco Meraki MXFortinet FortiGate
ManagementCloud-managed through the Meraki dashboardOn the firewall itself, or through FortiGate Cloud, Fortinet's hosted management and log retention service
Firmware and advisoriesMeraki can schedule upgrades through its bulk upgrade campaigns and emails notice in advance; admins can reschedule them, a month at a timeSecurity advisories are published on the second Tuesday of each month, and critical issues can be published out of cycle
High availabilityWarm spare: a second MX takes over after 3 seconds without heartbeats from the primary, and Meraki documents that the pair needs only one licenseActive-passive cluster; Fortinet's setup guide warns that connectivity can drop briefly while the cluster negotiates, so cluster changes go in a maintenance window
Remote accessCisco Secure Client (AnyConnect) with SAML sign-in, which works with Microsoft Entra ID and its MFAIPsec VPN with FortiClient; from FortiOS 7.6.3, SSL VPN tunnel mode is gone and its settings do not carry over in the upgrade

Other supported business firewalls can be taken over after a check of model, firmware and vendor support. A model that no longer gets security updates goes on a replacement plan instead.

What affects the cost of a managed firewall

We publish no rate card. These are the inputs that move the number:

FactorWhy it moves the price
Firewalls and sitesEach unit needs its own updates, backups, monitoring and rule reviews
High-availability pairsA second unit adds hardware and failover testing, though on Cisco Meraki MX the pair needs only one license
Rule base size and documentationA long rule base that nobody documented takes longer to review and to change safely
Remote users and VPN tunnelsEach account and site-to-site tunnel is something to set up, review and eventually remove
Log retentionKeeping logs for a year for an auditor, or feeding them to a SIEM, adds storage and review work
Compliance evidencePCI DSS, HIPAA or an insurer's questionnaire can require reviews and reports on a set schedule
Hardware and vendor subscriptionsThese are the vendor's charges and appear as separate lines in the proposal

Comparing quotes? How managed IT pricing works, and what sits outside the fee.

In a managed IT agreement, firewall management is part of the flat monthly fee per user, and hardware and vendor subscriptions are separate lines. On its own, it is quoted after a short scoping call, based mainly on the number of firewalls and sites.

Questions to ask any managed firewall provider

The phrase covers very different services. Ask these of any provider, including us; the answers belong in the agreement:

  • Who reads an alert at 3 a.m., and what may they change before calling you?
  • Who can request a rule change, who approves it, and where is the record kept?
  • How fast is a fix for an actively exploited flaw applied, and who decides when?
  • Is failover tested by pulling a line, or only configured?
  • Are hardware, vendor subscriptions and after-hours changes inside the fee or billed on top?
  • If you leave, do you get the admin credentials, the configuration backups and the rule documentation?

On round-the-clock coverage in general: What 24/7 IT support covers at NetSys.

Not sure your firewall still gets security updates?

Send the make, model and firmware version. We will tell you where it stands with the vendor and what managing it would involve.

Common Questions

Managed Firewall Services FAQs

What is a managed firewall?

A managed firewall is a business firewall that an outside team runs for you after installation: they keep its rules current, apply firmware and security updates, watch its alerts and keep the VPN and failover working. The hardware sits in your office or network closet, and the management happens remotely. You still decide what the business needs to reach; the provider turns those decisions into rules and keeps a record of each one.

What is included in managed firewall services?

At NetSys: rule reviews and approved rule changes, firmware and security updates in an agreed maintenance window, urgent fixes out of cycle, 24/7 monitoring with engineers acting on alerts, VPN account management, failover tested in an approved window, configuration backups, logs and a monthly summary. Hardware, the vendor's security subscriptions, network redesigns and new installations are scoped separately, and the table on this page shows the split.

How does onboarding work?

We start with admin access through a named account and an export of the current configuration, so nothing changes before there is a way back. An engineer then reads the rule base, the VPN and admin accounts, the firmware level and the support dates, and checks whether the management page answers from the internet. Quick fixes, such as removing former staff accounts, are approved with you first. The firewall then joins 24/7 monitoring, moves to a supported release in an agreed window, and you get a written summary of what we found and changed.

What affects the cost of a managed firewall?

Mainly the number of firewalls and sites, whether any are high-availability pairs, how large and undocumented the rule base is, how many remote users and VPN tunnels there are, how long logs must be kept and any compliance reporting. Hardware and the vendor's security subscriptions are the vendor's charges and appear as separate lines. Inside a NetSys managed IT agreement, firewall management is part of the flat monthly fee per user; on its own, we quote it after a short scoping call.

Who handles support and escalations?

Your staff reach the NetSys help desk, staffed seven days a week from 4 a.m. to 11 p.m. Eastern, and monitoring and emergency service run 24/7. A severe alert, such as the firewall going offline or a burst of failed VPN logins, follows the escalation path in your agreement at any hour, including any actions you approved us to take before we reach you. When a unit fails we work the vendor's support case, and when a line goes down we contact the carrier. Response times by severity are published on our managed IT services page.

What is a cloud-managed firewall?

It is a physical firewall at your office whose settings, firmware and logs are managed through the vendor's cloud dashboard rather than a local admin page. Cisco Meraki MX appliances work this way, and FortiGate firewalls can be managed through FortiGate Cloud. It is also different from firewall as a service, where the filtering itself runs in a provider's cloud instead of on a box in your office. Cloud management makes remote administration and changes across several sites simpler, but it does not decide what the rules should be or read the alerts; that part is still the managed service.

Can you manage a firewall that is not Cisco Meraki or Fortinet?

Often, yes. We design new installations on Cisco Meraki or Fortinet, and take over other business firewalls after checking the model, firmware version, support contract and subscriptions. If the vendor no longer ships security updates for the model, we will say so and plan a replacement rather than manage a device that can no longer be fixed.

How fast are urgent firewall fixes applied?

There is no single number, because it depends on whether the vendor has released a fix and whether the flaw is being exploited. When a flaw in your model appears on CISA's Known Exploited Vulnerabilities list or in an emergency vendor advisory, it is handled the day it appears rather than waiting for the next maintenance window. If no fix exists yet, we apply the vendor's mitigation, such as switching off the affected feature, and the emergency change still gets a configuration backup first.

Is a managed firewall worth it for a small business?

For most offices with staff, shared files and a VPN, yes, because the firewall faces the internet all day and its upkeep is exactly the work that slips. In one of our published case studies, a five-person office replaced the internet provider's router with a business-grade firewall, configured with sensible rules, secure remote access and logging, under the same month-to-month agreement as the rest of its IT. A business with no office network, whose staff all work remotely, gets more from endpoint protection and identity controls than from a perimeter firewall.

How is this different from your network security service?

Network security is the wider program: segmentation between staff, guest and device networks, remote-access policy, monitoring and who owns the response. Managed firewall services are the part of it that keeps the firewall itself current and accountable. The two can run under one agreement, and this page shows exactly what the firewall work covers.

Managed firewall

Give your firewall an owner.

Send the make and model, how many sites and remote users depend on it, and who changes the rules today. We will tell you what onboarding would check first, what the monthly service covers and what would be scoped separately.