Firewall configuration
Rules reviewed and rebuilt around what you actually need open, rather than inherited from years of temporary exceptions nobody removed.
Home › Network & Infrastructure Management
Firewalls, Wi-Fi, switching, and remote access designed to be boring — because the only time anyone notices the network is when it stops working.
Most small business networks weren't designed. They grew — a router from the internet provider, a switch added when desks ran out, an access point bought when the back office had no signal.
The result works, mostly. Then a video call drops in the conference room, guests are on the same network as the accounting server, and nobody can say what the firewall is actually allowing through because the rules were added one exception at a time over six years.
Our work is turning that into something documented and deliberate: equipment appropriate to your size, separated traffic, controlled remote access, and monitoring that tells you a switch is failing before your staff do.
Design, configuration, and ongoing management of the infrastructure everything else depends on.
Rules reviewed and rebuilt around what you actually need open, rather than inherited from years of temporary exceptions nobody removed.
Coverage planned for your actual floor space and device count, with guest traffic separated from business systems. Most Wi-Fi complaints are design problems, not bandwidth problems.
Guest devices, staff devices, servers, and equipment like printers and cameras kept on separate segments, so a compromise in one place doesn't reach everything.
Controlled paths into your network for staff working elsewhere — never remote desktop exposed directly to the internet, which remains a common and reliably exploited mistake.
Managed switches sized for your needs, with a documented map of what's connected where. Untangling an undocumented rack during an outage costs hours you don't have.
Alerting on device failures, saturated links, and connectivity loss — so problems are addressed before someone walks over to complain about the internet.
Four patterns that show up in most unmanaged networks. None are exotic; all of them matter.
Guests, staff laptops, servers, printers, and security cameras all on the same segment. Anything compromised can reach everything else — including devices that haven't had a firmware update in years.
Ports opened for a vendor in 2019, a system that no longer exists, or a remote access method that was replaced. Each one is an unnecessary way in that nobody is watching.
Home routers and access points handling forty devices, with no central management and no security updates since the manufacturer moved on to the next model.
No diagram, no record of what's plugged in where, no list of device passwords. Every troubleshooting session starts with rediscovering the network from scratch.
Network work is easy to oversell. A few situations where the honest answer is to spend less.
If you're a small team in a single room, fully cloud-based, with no on-site servers, a good business-grade router and access point may be genuinely sufficient. We'll tell you that.
If your Wi-Fi problem is one dead spot, that's often one access point rather than a network redesign. We'd rather do the small fix and be there when you actually grow.
And if you're being told you need a network refresh without anyone doing a site survey first, get a second opinion. Recommendations made without measurement are sales, not engineering.
Usually not. Most office Wi-Fi complaints come from coverage and capacity — too few access points, consumer gear handling more devices than it was built for, or interference from neighbouring businesses. A site survey tells you which before anyone spends money.
Consumer gear works until it doesn't. It usually lacks VLAN support, central management, and long-term security updates. Under ten people in one room it may be fine; beyond that the failures get expensive in staff time.
Always. Guest devices are unmanaged and may be compromised. On a shared network they can reach your servers, printers, and workstations. Separating them is one of the highest-value changes available.
Depends what people need to reach. Cloud-based applications may not need one. File shares or software hosted in your office still require controlled access — but never remote desktop exposed to the internet.
At least annually, and after any significant change. Rules accumulate as temporary exceptions that never get removed, and reviews routinely find ports open to systems decommissioned years ago.
Less than most assume, but rarely none — you still need connectivity, a firewall, and Wi-Fi. The real question is whether the servers you're still maintaining are earning their cost.
Ongoing support and monitoring across your whole environment, network included.
Segmentation and perimeter controls are security work as much as network work.
Secure configuration of identity, email, and collaboration tools.
Tell us what you're running and what's frustrating people. We'll tell you what's worth fixing and what isn't — including when the answer is a single access point rather than a project.