Security

Managed Firewall Services — What Is Included, Costs and When to Buy

G Gurpreet Singh April 14, 2024 6 min read
Animated diagram for Managed Firewall Services, showing traffic arriving at a policy wall where two flows are allowed through and two are dropped at the boundary

A managed firewall is a firewall that a third party configures, monitors and maintains on your behalf. The hardware may sit in your rack or in the provider’s cloud; what you are buying is the operational responsibility, not the box.

The reason organisations buy it is rarely the technology. It is that a firewall left unmanaged degrades: rules accumulate, nobody removes the temporary ones, firmware falls behind, and alerts go unread because nobody is on shift at 3 a.m.

What a Managed Firewall Service Includes

ServiceWhat it means in practice
Initial design and deploymentSizing, zone design, base ruleset, HA pair configuration, migration from the existing device
Rule changesYou raise a request, they implement it. Check the SLA and whether there is a monthly quota.
Patching and firmwareSecurity updates applied in a maintenance window, the single most commonly neglected task in-house
24/7 monitoringHealth, availability, and security alerting outside your working hours
Log retentionCentralised storage, often the compliance driver for buying the service
Threat signature updatesIPS, antivirus, URL filtering and application signatures kept current
ReportingMonthly summaries of traffic, blocked threats, rule changes, and policy drift
Incident responseVaries enormously, from “we email you” to full containment. This is the clause to read carefully.
Backup and recoveryConfiguration backups and a tested restore procedure

Deployment Models

  • On-premises, provider-managed. A physical appliance in your rack that the provider administers remotely. You keep local traffic inspection and low latency; they keep the login.
  • Cloud-hosted (FWaaS). Traffic is routed to the provider’s cloud for inspection. Scales without hardware and suits distributed sites and remote workers; adds latency and a hard dependency on the connection to the provider.
  • Virtual appliance in your cloud. A firewall VM in your AWS, Azure or GCP environment, managed by the provider. Common for organisations with substantial cloud footprints.
  • Hybrid. On-premises hardware for site traffic, cloud inspection for remote users. Increasingly the default as SASE offerings mature.

Realistic Costs

Organisation sizeTypical monthly rangeUsually covers
Small business, single site$150 – $600One appliance, business-hours support, basic reporting
Mid-size, several sites$800 – $4,000HA pairs, 24/7 monitoring, IPS and content filtering, log retention
Enterprise$5,000+Multi-site, SIEM integration, dedicated engineers, custom SLAs

Compare against the honest in-house cost: appliance and licences amortised, plus a fraction of a security engineer’s salary, plus the on-call coverage you either fund or quietly do without. For most organisations under a few hundred staff, the managed option is cheaper than a genuine 24/7 in-house capability, and it is the 24/7 part that is expensive, not the box.

When It Makes Sense

Buy managed if

  • You have no dedicated security staff, or one person who is also doing everything else.
  • You need 24/7 coverage and cannot staff a rota.
  • Compliance requires demonstrable log retention, change control and review evidence.
  • Firmware and signature updates are already slipping, this is the most common honest reason.
  • You are running multiple sites and want consistent policy across all of them.

Keep it in-house if

  • You have a capable network security team already.
  • Your rules change constantly and daily and a ticket-based SLA would obstruct you.
  • Regulation or policy prevents third-party access to your infrastructure.
  • Your environment is unusual enough that a standardised service will not fit it.

The Shared-Responsibility Gaps

This is where managed firewall relationships go wrong. Establish in writing, before signing:

  • Who defines policy? Providers implement rules. Deciding what should be allowed between your business systems is your job, they do not know your applications.
  • What is the change SLA, and is there a quota? “Four-hour response” for a standard change and “next business day” are very different operationally. Some contracts cap changes per month and bill beyond it.
  • Emergency change process. How do you get a rule pushed at 2 a.m. during an incident, and who is authorised to request it?
  • Does “monitoring” mean alerting or responding? Many contracts sold as monitoring send an email and stop there.
  • Do you retain admin access? Read-only visibility at minimum. Being unable to see your own ruleset is a poor position during an incident.
  • Log ownership and export. Can you pull raw logs into your own SIEM, and what happens to them when the contract ends?
  • Exit process. How do you get the configuration out and move to another provider or in-house? Ask before you need to.

What a Managed Firewall Does Not Cover

The firewall is one control at one boundary. It does not address:

  • Endpoint compromise, that is EDR’s job.
  • Lateral movement inside a segment it does not sit between. See network security monitoring.
  • Phishing and credential theft, which arrive over connections you already permit.
  • Layer 2 attacks, ARP poisoning, rogue DHCP, MAC flooding, which happen below it.
  • Identity and access management.

Buying a managed firewall and treating security as handled is the failure mode to avoid.

Questions to Ask a Provider

  1. Which vendor and model, and is the licensing included or passed through?
  2. What is the change SLA, and is there a monthly change limit?
  3. Who is on shift outside business hours, and where?
  4. How long are logs retained, in what format, and can I export them?
  5. Do I get read-only or full admin access to the device?
  6. What does your incident response actually do, notify, or contain?
  7. How often is the ruleset reviewed for unused and overly broad rules?
  8. What is your patching cadence, and how are emergency patches handled?
  9. How is the service tested? Do you support customer penetration testing?
  10. What is the offboarding process and how is the configuration handed back?

Frequently Asked Questions

Is a managed firewall the same as a firewall as a service?

Not quite. FWaaS specifically means the firewall runs in the provider’s cloud with your traffic routed to it. A managed firewall can equally be your own on-premises appliance that someone else administers.

Do I still need my own security staff?

Yes, someone must own policy decisions, approve changes, and act on escalations. The provider operates the control; they do not own your risk.

Is a managed firewall more secure than one I run myself?

Only if you would not otherwise patch it, review the rules, or watch the alerts. A well-run in-house firewall beats an averagely-run managed one. Most unmanaged firewalls are not well-run, which is the honest case for the service.

What happens if the provider has an outage?

With cloud-based inspection, your traffic path may be affected, ask what the failover behaviour is and whether it fails open or closed. With on-premises hardware the firewall keeps enforcing its current policy; you simply cannot get changes made.

Can I keep my existing firewall hardware?

Often yes, if it is a supported model still under maintenance. Providers prefer their standard platforms, so expect a discount for standardising and a premium for keeping something unusual.

How is it different from a hardware firewall I buy outright?

The device may be identical. What changes is who configures it, patches it, watches it and is contractually accountable when it is misconfigured.

GU
Written by

Gurpreet Singh

Hey! I"m Gurpreet Singh and I Have 7+ Years of experience in the Network & Security Domain as well as the Cloud Infra Domain. I am Certified with Cisco ( CCNA ), CheckPoint ( CCSA ), 1xAWS, 3xAZURE, and 3xNSE. So I love to share my tech knowledge with you.

Leave a Reply

Your email address will not be published. Required fields are marked *