
Managed Firewall Services: Rules, Updates and 24/7 Monitoring
A managed firewall service is ongoing care of your business firewall by an outside engineering team: rule changes under change control, firmware and security updates, 24/7 monitoring with an engineer acting on the alerts, and VPN and failover settings that keep working. NetSys runs that service on Cisco Meraki and Fortinet firewalls, and on other supported business firewalls after a check of the model, firmware and vendor support.
The short answer
Managed firewall services cover the work a firewall needs after it is installed, which is most of its life: reviewing rules, approving changes, applying firmware and security updates, managing VPN accounts, testing failover, keeping logs and acting on alerts. NetSys includes this in every managed IT agreement and offers it on its own to businesses with in-house IT. Hardware and the vendor's security subscriptions are separate lines, and we publish no rate card.
Closest related page: Network security and firewall management. That page covers the wider network security program, from segmentation to remote-access policy; this one covers the firewall itself: what managing it involves, what is included and what moves the price.
A firewall gets configured once and then changed for years. Every new vendor connection and remote worker adds a rule, few rules are ever removed, and the firmware falls behind because updating it takes the office offline for a few minutes. Eventually the device still works every morning but no longer matches the business, while its VPN portal faces the internet with nobody reading the log.
NIST's firewall guidance, SP 800-41, describes the routine most small offices skip: rule changes handled through formal change control, periodic rule reviews, patches applied as vendors release them, regular configuration backups and logs monitored continuously. A managed firewall service is that routine with a name on it, whether there is one firewall in one office or one at every location, joined over site-to-site VPN.
The routine behind a managed firewall
Rule changes come from the named contacts in your agreement, get tested, and are recorded with the reason and a way back. Firmware follows the vendor's advisories: Fortinet publishes its security advisories on the second Tuesday of each month, and a fix for a flaw on CISA's Known Exploited Vulnerabilities list moves ahead of the queue. Updates are installed in your agreed maintenance window, after a configuration backup. The firewall reports into the same 24/7 monitoring as your computers and servers, and an engineer who knows your network picks up the alerts. Each month you get a short summary of the firmware level, what changed and what needs a decision from you.
What managed firewall services include
Configuration and rule reviews
Every rule gets an owner and a reason, or it comes out.
- The rule base exported and read line by line at onboarding, with unused, duplicate and overly broad rules flagged
- Each material rule recorded with its purpose, who asked for it and when it is next reviewed
- Periodic reviews of every change since the last review, as NIST SP 800-41 recommends
- Admin access limited to named accounts with MFA where the platform supports it, and the management page kept off the internet
Firmware and security updates
Vendor fixes in your maintenance window, urgent ones sooner.
- Vendor advisories tracked against your exact model and firmware, with subscription and support renewal dates alongside
- Updates installed in the window agreed with you, after a configuration backup
- Fixes for flaws on CISA's Known Exploited Vulnerabilities list handled out of cycle
- Release notes read before every upgrade, since a new version can remove or change a feature you rely on
24/7 monitoring and alert response
Monitoring raises the alert; an engineer decides what happens next.
- The firewall reporting into the same 24/7 monitoring as your computers and servers, through NinjaOne
- Alerts on the events NIST SP 800-41 lists, such as rule changes, reboots and failover, plus repeated failed VPN logins
- Severe alerts follow the escalation path in your agreement at any hour; routine ones wait for staffed help desk hours
- Actions we may take before calling you, such as disabling a compromised VPN account, agreed in writing in advance
Change control
No change without a request, a test and a way back.
- Changes requested by the contacts named in your agreement, not by whoever happens to call
- Each change recorded with what it does, who approved it and how to reverse it
- Configuration backed up before the change and checked from a user's side afterward
- The platform's own audit trail kept as evidence, such as the change log in the Cisco Meraki dashboard
High availability and ISP failover
A second internet line, and a second firewall where downtime costs more than the unit.
- A backup internet line or cellular failover configured on the firewall and kept current
- Warm-spare pairs on Cisco Meraki MX, or active-passive clusters on FortiGate, where the business cannot wait for a replacement unit
- Failover tested in an approved window by pulling the primary line and checking what keeps working
- Circuit IDs and carrier contacts recorded, so a line fault reaches the carrier quickly
VPN and remote access
Remote access that checks who is connecting.
- Site-to-site VPN between offices, and remote-access VPN for staff who need the office network
- VPN sign-in through Microsoft Entra ID with MFA where the platform supports it, as Cisco Secure Client does on Meraki MX
- Named VPN accounts only, removed the day someone leaves, with vendor access given an end date
- FortiGate remote access moved off SSL VPN tunnel mode before any upgrade to FortiOS 7.6.3 or later, where tunnel mode no longer exists
Logging and reporting
Logs kept off the box, and a report written for an owner.
- Logs kept on the firewall and copied to central storage, as NIST SP 800-41 advises
- A monthly summary of firmware level, updates applied, changes made and decisions waiting on you
- Change records and update history ready for a cyber insurance questionnaire or an audit
- Longer retention and correlation with identity logs through SOC monitoring, where a framework calls for it
Why businesses hand their firewall to NetSys
Tell us the firewall make and model, how many offices and remote users depend on it, and who changes the rules today. A NetSys engineer, not a salesperson, will tell you what onboarding would check first and what the monthly service would cover. Call 845-203-3914 or request a call.
Who does the work: meet the NetSys team on our About page.
- Firewall, switching, Wi-Fi and failover designed on Cisco Meraki or Fortinet, the platforms our engineers build on
- Monitoring that runs 24/7, with severe alerts escalated at any hour to engineers who already know your network
- Every rule change recorded with an owner, an approval and a way to reverse it
- Firmware and security subscriptions kept current as part of the agreement
- The firewall, your computers, Microsoft 365 and the backups under one agreement, so an alert never falls between two vendors
- Running business networks since 1998, from one office in Brooklyn, on month-to-month agreements
Managed Firewall Services in practice
- Retail
Seven-location clothing retail chain
Management of 56 computers, point-of-sale network support, endpoint protection, and standardized Wi-Fi and firewall configurations.
Client names are withheld. Each card is the scope of a real NetSys engagement, as delivered.
What is included, and what is project work
The monthly service covers running the firewall you have. Work with a start and an end, and anything the vendor charges for, is scoped separately so it can be planned and approved:
| Area | Included in the monthly service | Scoped or billed separately |
|---|---|---|
| Rules and configuration | Rule reviews, approved rule changes, configuration backups and control of admin accounts | A network redesign or a new segmentation plan |
| Updates | Firmware and security updates in the agreed window, urgent fixes out of cycle, renewal dates tracked | The vendor's security subscriptions and support contracts themselves |
| Monitoring | 24/7 monitoring of the firewall, with engineers acting on alerts | Incident investigation beyond the agreed scope, which our incident response service covers |
| Remote access | VPN accounts added and removed, and MFA on VPN sign-in where the platform supports it | Replacing the VPN with zero trust network access |
| Resilience | Failover settings kept current and tested in an approved window | A second firewall or a backup internet line, bought and installed |
| Hardware | Vendor support cases and replacement coordination when a unit fails | New or replacement firewall hardware, and installing it |
Firewall management sits inside every NetSys managed IT agreement and is available on its own for businesses with in-house IT. Coverage hours, escalation contacts and the actions we may take before calling you are written into the agreement.
How onboarding works
Taking over a firewall follows the same order every time, whether it protects one office or several:
- Access: we get admin access through a named account and record the model, serial number, firmware version, support contract and subscription dates.
- Backup: the current configuration is exported and stored before anything changes, so every later step has a way back.
- Baseline review: an engineer reads the rule base, the VPN and admin accounts and the failover settings, and checks whether the management page answers from the internet.
- Quick fixes: former staff accounts, shared logins and rules nobody can explain are removed or restricted, each approved with you first.
- Monitoring: the firewall joins 24/7 monitoring, and the after-hours contacts and pre-approved actions are agreed in writing.
- Firmware: the firewall is brought to a supported release in an agreed window, after any feature changes the release notes call for.
- Handover: you get a written summary of what we found and changed, which rules still need an owner and which hardware or subscriptions are near the end of support.
Timing depends on the number of firewalls and sites and on how quickly the current provider hands over admin access, so target dates go in the proposal.
Cisco Meraki and Fortinet: what differs by platform
The routine is the same on both platforms we design on; the mechanics differ. Checked against Cisco Meraki and Fortinet documentation in October 2026:
| Task | Cisco Meraki MX | Fortinet FortiGate |
|---|---|---|
| Management | Cloud-managed through the Meraki dashboard | On the firewall itself, or through FortiGate Cloud, Fortinet's hosted management and log retention service |
| Firmware and advisories | Meraki can schedule upgrades through its bulk upgrade campaigns and emails notice in advance; admins can reschedule them, a month at a time | Security advisories are published on the second Tuesday of each month, and critical issues can be published out of cycle |
| High availability | Warm spare: a second MX takes over after 3 seconds without heartbeats from the primary, and Meraki documents that the pair needs only one license | Active-passive cluster; Fortinet's setup guide warns that connectivity can drop briefly while the cluster negotiates, so cluster changes go in a maintenance window |
| Remote access | Cisco Secure Client (AnyConnect) with SAML sign-in, which works with Microsoft Entra ID and its MFA | IPsec VPN with FortiClient; from FortiOS 7.6.3, SSL VPN tunnel mode is gone and its settings do not carry over in the upgrade |
Other supported business firewalls can be taken over after a check of model, firmware and vendor support. A model that no longer gets security updates goes on a replacement plan instead.
What affects the cost of a managed firewall
We publish no rate card. These are the inputs that move the number:
| Factor | Why it moves the price |
|---|---|
| Firewalls and sites | Each unit needs its own updates, backups, monitoring and rule reviews |
| High-availability pairs | A second unit adds hardware and failover testing, though on Cisco Meraki MX the pair needs only one license |
| Rule base size and documentation | A long rule base that nobody documented takes longer to review and to change safely |
| Remote users and VPN tunnels | Each account and site-to-site tunnel is something to set up, review and eventually remove |
| Log retention | Keeping logs for a year for an auditor, or feeding them to a SIEM, adds storage and review work |
| Compliance evidence | PCI DSS, HIPAA or an insurer's questionnaire can require reviews and reports on a set schedule |
| Hardware and vendor subscriptions | These are the vendor's charges and appear as separate lines in the proposal |
Comparing quotes? How managed IT pricing works, and what sits outside the fee.
In a managed IT agreement, firewall management is part of the flat monthly fee per user, and hardware and vendor subscriptions are separate lines. On its own, it is quoted after a short scoping call, based mainly on the number of firewalls and sites.
Questions to ask any managed firewall provider
The phrase covers very different services. Ask these of any provider, including us; the answers belong in the agreement:
- Who reads an alert at 3 a.m., and what may they change before calling you?
- Who can request a rule change, who approves it, and where is the record kept?
- How fast is a fix for an actively exploited flaw applied, and who decides when?
- Is failover tested by pulling a line, or only configured?
- Are hardware, vendor subscriptions and after-hours changes inside the fee or billed on top?
- If you leave, do you get the admin credentials, the configuration backups and the rule documentation?
On round-the-clock coverage in general: What 24/7 IT support covers at NetSys.
Not sure your firewall still gets security updates?
Send the make, model and firmware version. We will tell you where it stands with the vendor and what managing it would involve.
Managed Firewall Services FAQs
What is a managed firewall?
A managed firewall is a business firewall that an outside team runs for you after installation: they keep its rules current, apply firmware and security updates, watch its alerts and keep the VPN and failover working. The hardware sits in your office or network closet, and the management happens remotely. You still decide what the business needs to reach; the provider turns those decisions into rules and keeps a record of each one.
What is included in managed firewall services?
At NetSys: rule reviews and approved rule changes, firmware and security updates in an agreed maintenance window, urgent fixes out of cycle, 24/7 monitoring with engineers acting on alerts, VPN account management, failover tested in an approved window, configuration backups, logs and a monthly summary. Hardware, the vendor's security subscriptions, network redesigns and new installations are scoped separately, and the table on this page shows the split.
How does onboarding work?
We start with admin access through a named account and an export of the current configuration, so nothing changes before there is a way back. An engineer then reads the rule base, the VPN and admin accounts, the firmware level and the support dates, and checks whether the management page answers from the internet. Quick fixes, such as removing former staff accounts, are approved with you first. The firewall then joins 24/7 monitoring, moves to a supported release in an agreed window, and you get a written summary of what we found and changed.
What affects the cost of a managed firewall?
Mainly the number of firewalls and sites, whether any are high-availability pairs, how large and undocumented the rule base is, how many remote users and VPN tunnels there are, how long logs must be kept and any compliance reporting. Hardware and the vendor's security subscriptions are the vendor's charges and appear as separate lines. Inside a NetSys managed IT agreement, firewall management is part of the flat monthly fee per user; on its own, we quote it after a short scoping call.
Who handles support and escalations?
Your staff reach the NetSys help desk, staffed seven days a week from 4 a.m. to 11 p.m. Eastern, and monitoring and emergency service run 24/7. A severe alert, such as the firewall going offline or a burst of failed VPN logins, follows the escalation path in your agreement at any hour, including any actions you approved us to take before we reach you. When a unit fails we work the vendor's support case, and when a line goes down we contact the carrier. Response times by severity are published on our managed IT services page.
What is a cloud-managed firewall?
It is a physical firewall at your office whose settings, firmware and logs are managed through the vendor's cloud dashboard rather than a local admin page. Cisco Meraki MX appliances work this way, and FortiGate firewalls can be managed through FortiGate Cloud. It is also different from firewall as a service, where the filtering itself runs in a provider's cloud instead of on a box in your office. Cloud management makes remote administration and changes across several sites simpler, but it does not decide what the rules should be or read the alerts; that part is still the managed service.
Can you manage a firewall that is not Cisco Meraki or Fortinet?
Often, yes. We design new installations on Cisco Meraki or Fortinet, and take over other business firewalls after checking the model, firmware version, support contract and subscriptions. If the vendor no longer ships security updates for the model, we will say so and plan a replacement rather than manage a device that can no longer be fixed.
How fast are urgent firewall fixes applied?
There is no single number, because it depends on whether the vendor has released a fix and whether the flaw is being exploited. When a flaw in your model appears on CISA's Known Exploited Vulnerabilities list or in an emergency vendor advisory, it is handled the day it appears rather than waiting for the next maintenance window. If no fix exists yet, we apply the vendor's mitigation, such as switching off the affected feature, and the emergency change still gets a configuration backup first.
Is a managed firewall worth it for a small business?
For most offices with staff, shared files and a VPN, yes, because the firewall faces the internet all day and its upkeep is exactly the work that slips. In one of our published case studies, a five-person office replaced the internet provider's router with a business-grade firewall, configured with sensible rules, secure remote access and logging, under the same month-to-month agreement as the rest of its IT. A business with no office network, whose staff all work remotely, gets more from endpoint protection and identity controls than from a perimeter firewall.
How is this different from your network security service?
Network security is the wider program: segmentation between staff, guest and device networks, remote-access policy, monitoring and who owns the response. Managed firewall services are the part of it that keeps the firewall itself current and accountable. The two can run under one agreement, and this page shows exactly what the firewall work covers.
Sources and technical references
- NIST SP 800-41 Rev. 1, Guidelines on Firewalls and Firewall Policy: change control, rule reviews, patching, backups and logging
- CISA Known Exploited Vulnerabilities catalog
- CISA and partners: guidance and strategies to protect network edge devices such as firewalls and VPN gateways
- Fortinet security vulnerability policy: advisories on the second Tuesday of each month, critical issues out of cycle
- Fortinet FortiOS release notes: SSL VPN tunnel mode replaced with IPsec VPN from FortiOS 7.6.3
- Fortinet FortiOS administration guide: HA active-passive cluster setup
- Fortinet FortiOS administration guide: FortiGate Cloud, hosted management and log retention
- Cisco Meraki: MX warm spare high-availability pair
- Cisco Meraki: managing firmware upgrades
- Cisco Meraki: the organization change log
- Cisco Meraki: Secure Client (AnyConnect) authentication methods on the MX, including SAML with Entra ID
Guides on this topic
- Network security and firewall management: the wider program
- Network and Wi-Fi management: switches, circuits and carriers
- Business Wi-Fi installation and office network setup
- Vulnerability management, including scans of firewalls and VPN appliances
- Patch management services for computers, servers and applications
- SOC monitoring for firewall and identity logs
- Zero trust access instead of a flat VPN
- SonicWall VPN attacks: what small businesses must do now
- Does your small business need a firewall?
- VPN vs ZTNA: remote access for a small business
- Business internet failover: 8 questions owners ask
- What a next-generation firewall is
- Case study: firewalls at seven sites joined in a VPN mesh for a medical practice
Give your firewall an owner.
Send the make and model, how many sites and remote users depend on it, and who changes the rules today. We will tell you what onboarding would check first, what the monthly service covers and what would be scoped separately.
