The project is about more than the device. Protection depends on the rules configured, the remote access the firewall controls, its updates and the follow-up on its logs.
Short answer
You describe your needs once: your request is reviewed by the Courtier TI team, then entrusted to the IT services company that will prepare your quote.
What the quote should cover
- The proposed device and the security features turned on
- The planned network zones and the rules between them
- How remote access and authentication will be configured
- Updates, monitoring and rule reviews after installation
- The documentation and administrator credentials handed over to the business
What a firewall project involves
- A review of the current setup: Internet connection, the Internet provider's router, network equipment, services reachable from the Internet and existing remote access.
- Defining network zones: staff, guests, servers, phones, printers and connected devices, payment terminals.
- Choosing the device based on the Internet connection, the security features needed and how updates will be handled.
- Configuring the rules, starting from what must be allowed rather than allowing everything by default.
- Setting up remote access through a virtual private network (VPN) with two-factor authentication.
- Turning on DNS filtering and event logging.
- Documenting the rules and handing the administrator credentials over to the business.
- Follow-up: firmware updates, review of rules and alerts.
Questions to ask yourself before requesting a quote
- Which services must be reachable from outside: email, file server, cameras, business software?
- How many employees work remotely, and which resources do they need?
- Do you have point-of-sale terminals or financial systems to isolate?
- Do you have more than one office to connect?
- Who will monitor alerts and apply updates after the installation?
- Who currently holds the administrator passwords for your router and current firewall?
Risks and pitfalls to avoid
- Keeping default settings. The Canadian Centre for Cyber Security notes that many wireless devices come with known usernames and passwords and firewall rules that allow everything through.
- Opening remote access without a second factor. The Centre recommends requiring VPN connectivity with two-factor authentication for all remote access into corporate networks.
- Neglecting VPN updates. The Centre states that threat actors attack vulnerabilities within VPNs and that outdated systems increase this risk.
- Turning on split tunnelling. The Centre explains that it allows possible bridging between the open Internet and the secure tunnel, and recommends avoiding it as much as possible.
- Leaving a flat network. Without segmentation, one compromised device can reach the rest of the network. The Centre recommends isolating Internet-facing servers and point-of-sale terminals in particular.
- Accepting rules nobody documents: every change becomes risky, especially if the IT services company changes.
What to specify in your request
- The type and speed of your Internet connection, and whether there is a backup connection
- The approximate number of users and devices
- Remote access needs: who, to what, from which devices
- The offices to connect
- The zones to separate: guests, servers, phones, connected devices, payments
- The services to make reachable from the Internet
- The follow-up expected after installation: updates, monitoring, rule reviews
- The credentials and documentation to be handed over to you
You can then describe your project: the team will contact you to clarify your needs and send you a quote.
Frequently asked questions
Is our Internet provider's router enough?
The Canadian Centre for Cyber Security recommends dedicated firewalls at the boundary between the corporate network and the Internet. The provider's router may include firewall features; the question is whether it supports segmentation, a VPN with two factors, logging and managed updates.
What is a DNS firewall?
It is a filter that prevents devices on the network from connecting to known malicious domains. The Canadian Centre for Cyber Security recommends implementing one for outbound DNS requests, and considering it for content filtering to limit the websites reachable from the corporate network.
Do we need a VPN for remote work?
If employees connect to the corporate network remotely, the Canadian Centre for Cyber Security recommends a VPN gateway with two-factor authentication, and a firewall between the VPN termination point and the internal network. It also recommends phishing-resistant authentication factors.
Who looks after the firewall after installation?
Spell it out in your request: updates, log monitoring, rule reviews and changes. For small and medium organizations, the Canadian Centre for Cyber Security recommends enabling automatic patching for all software and hardware, or establishing full vulnerability and patch management. See also our guide on choosing an IT services provider.
Should our payment terminals be separated from the rest of the network?
The Canadian Centre for Cyber Security recommends isolating point-of-sale systems from the Internet and other areas of the corporate network with a firewall, and considering the Payment Card Industry Data Security Standard (PCI DSS).