Next Generation Firewall for a secure IT environment

Firewall

As part of a managed firewall, we act as your external IT department, proactively configuring, administering, maintaining and monitoring your security-critical firewall and your network.

A professional firewall is security-critical for your company.
Managed firewall by IT professionals

What does a firewall do?

In the field of IT security the firewall plays an absolutely central role, because the firewall monitors and regulates the data traffic between your company network and external networks, such as the internet. As the name suggests, it works like a barrier that can detect and block unwanted and dangerous data packets. At the same time, it lets legitimate data packets pass. A firewall consists of hardware and software and protects your network against malware, ransomware and other unauthorized access.

Imagine you want to host an event at your premises and use admission control to ensure that only invited guests get in and unwanted guests stay outside.

Applied to a conventional firewall, this means: outbound data traffic is always let through, while inbound data traffic is only allowed in if it was actually requested.

  • Protocol inspection
  • Port inspection

What is a next generation firewall?

Compared to a conventional firewall, a so-called next generation firewall (NGFW) offers more extensive and more powerful features and security components. These make it possible to detect, analyze and block in real time even elaborately disguised cyberattacks at the application level.

This time, in addition to the ticket check, there is also a body search and a bag check for potentially unwanted items. In addition, security staff patrol the building and the exits are monitored as well.

Your next generation firewall therefore does considerably more. It analyzes the incoming and outgoing data packets (Deep Packet Inspection) as well as the data flows within the network using rules, techniques, behavioral patterns and security threat data (Intrusion Detection Services), and can thus alert those responsible for security.

  • Protocol inspection
  • Port inspection
  • Data analysis at the application level
Next generation firewalls provide multi-layered protection

Security features of the next gen firewall

Cyberattacks are becoming increasingly technical and thus more sophisticated. For this reason, security technologies must also evolve proactively to offer companies efficient, multi-layered protection. Thanks to their technical complexity, next generation firewalls offer remarkable efficiency in responding appropriately to security breaches. Below we present a selection of the features – without going too deep into technical details.

When setting up the firewall, access from individual countries can be blocked outright. Our experience over recent years has shown that this approach can ward off a large proportion of attacks.

Encrypting data traffic is essential for confidentiality and data protection. However, cybercriminals also use encrypted malware for their attacks. That is why next generation firewalls (NGFW’s) use specific decryption techniques to fend off these threats (SSL/TLS decryption).

In addition, NGFW’s are programmed and configured to detect suspicious activity based on signatures, attack and behavioral patterns and to block it immediately (Intrusion Prevention System). This threat data (threat intelligence feeds) is continuously updated and refined by IT security companies, government agencies and cyber defense centers. Some NGFW’s also use AI and machine learning to analyze large volumes of data for potential threats.

When it comes to cybersecurity, many people initially only think of attacks from outside. However, a not insignificant share also comes from attacks originating inside the company.

Your next generation firewall also offers ways to optimally protect the network from within. Network segmentation plays a major role here, because sensitive areas can be better isolated and equipped with access controls and security policies. This approach makes it difficult or even impossible for attackers to gain further access within the network. You must also make sure that the Wi-Fi access for your guests/customers is always kept separate from that of your employees.

Network segmentation is one aspect of the legal compliance requirements!

Another feature for increasing internal IT security is the deactivation of unused ports. This helps you prevent unwanted and unauthorized devices or connections from being attached to your network.

Additional configurations, such as the assignment of MAC addresses to individual ports, can furthermore ensure that only the registered device with the exactly matching MAC address can connect. (MAC stands for Media Access Control and in this case has nothing to do with the company Apple.)

Using a filter function, you can block connections to and from certain unwanted websites and online services outright.

Offering remote workplaces, such as working from home, is important for companies to stay competitive in the race for skilled staff. However, these workplaces must also be securely connected to the company network. The integrated VPN features of the next generation firewall enable you to exchange data and information securely within your company.

To avoid bottlenecks and ensure optimal network performance, next generation firewalls (NGFW’s) enable the prioritization of data streams for critical applications such as VoIP telephony and video transmissions in the data traffic.

At the same time, the “less important applications” are assigned less bandwidth. This bandwidth management can be controlled and optimized via the NGFW.

In most cases, an internet outage brings the entire operation to a standstill. To prevent this, two independent internet connections can be set up. (Despite paying twice for internet service, this security measure is still extremely worthwhile! Important for you to know: our service price remains unchanged!)

The NGFW permanently checks the availability of the internet. In the event of an outage, it automatically switches to the second line and at the same time informs the IT security staff about the outage and the measures taken.

Outsource the management of your firewall if you do not have specialist staff of your own!

What is a managed firewall?

Operating a security-critical firewall is a continuous process. Nowadays, it is no longer enough to buy a firewall once, implement it and expect to run it without much maintenance effort. A simple Fritz!Box alone also does not offer companies sufficient protection against the growing cyber threat — because the threat level, driven in part by the use of AI in the cyber arms race, is high.

Instead, the security settings must be constantly updated, monitored and adapted to the latest attack methods. The right configuration and maintenance are essential prerequisites and should only be carried out by qualified specialists. If you do not have these IT experts available, external IT service providers – like us – can help and support you.

Benefits of managed firewall services

As an IT systems house, we take care of your systems proactively with the necessary know-how.

We analyze your network in order to set up the firewall optimally. We also adapt it to your current and future needs — always, of course, with security aspects in mind. In addition, we administer and monitor your systems in real time through comprehensive monitoring (remote management monitoring).

A competent IT support team is on hand for questions and technical assistance.

By the way: the next generation firewall incl. service is already an integral part of our IT Service Flat Rate Pro. With it, you get a comprehensive service and IT security package at predictable IT costs!

  • Help choosing the right firewall systems

  • Installation, configuration and administration

  • Predictable firewall costs, short contract terms

  • Proactive maintenance and care

  • Real-time monitoring 24/7

  • IT support via a helpdesk

Prices

One-time cost per user
Next Generation Firewall basic installation 99,90 €
Ongoing cost per user per month
Next Generation Firewall incl. service17,90 €*

* Our IT Service Flat Rate Pro already includes the Next Generation Firewall incl. service.

FAQ

  • Administration of the Next Generation Firewall
  • Real-time monitoring
  • Hotline and remote support
  • On-site troubleshooting only if the problem cannot be resolved remotely (travel is charged separately).
  • Next Generation Firewall as a rental device
  • Basic installation and costs for hardware such as switches and access points, including their installation
  • Services / emergencies outside business hours (billed according to the agreed rate schedule)
  • Work not originating from the Next Generation Firewall or the network.
  • Travel costs are charged at the agreed flat rate.
  • Relocation, e.g. if you move into new office premises
  • Work we carry out in connection with third-party solutions.
  • All IT technician working hours for resolving problems originating from your Next Generation Firewall are already covered. These are the costs that other providers bill additionally as time and effort — costs you as a customer cannot predict.
  • With us you get administration, maintenance, IT service and the rental device in one fixed monthly flat rate. That gives you predictable costs with no “surprises”.
  • For companies with more than 5 employees, we recommend using a professional firewall.
  • All IT systems and devices must be protected via this Next Generation Firewall.
  • Services related to IT security incidents, e.g. force majeure, hacking, gross negligence or intent, are not included.
  • The contract term is 6 months, after which it can be cancelled monthly
  • The rental device must be returned in full at the end of the term! In case of damage, a reduced purchase price will be charged.

We offer you a guaranteed response time of 6 hours within our working hours for system-critical problems. During working hours (Monday – Friday from 8 a.m. to 12 p.m. and 1 – 5 p.m.) you can reach our 1st-level support by phone, e-mail or via the contact form: IT support ticket.

Outside business hours, you can reach us via our emergency support (chargeable).

  • Express surcharge: 89,90 € (one-time)
  • Weekdays until 10 p.m. and from 6 a.m., Saturday 8 a.m. to 5 p.m.: 60 € per hour
  • Weekdays after 10 p.m. and before 6 a.m., Saturday after 5 p.m. and before 8 a.m., Sunday/public holidays 8 a.m. to 5 p.m.: 120 € per hour

What else might interest you

Interested in a Managed Firewall?

Feel free to contact us for a no-obligation consultation.

Phone: +49 7551 80194-0 or by
e-mail to info@computer-spezialisten.de

We are here for you!

Do you need an IT solution and are looking for an IT service provider who advises and supports you competently?
Then you have come to the right place! Simply arrange an appointment directly.

MCL Computer-Spezialisten.de GmbH