Managed Firewall Services for New Zealand Businesses
Your firewall needs attention as your business changes. Exodesk manages the rules, the security updates, the monitoring and the change requests, so someone is responsible for keeping it aligned with how you work.
Supporting New Zealand businesses since 1989
What is a managed firewall?
A managed firewall is a firewall that an IT provider configures, monitors and maintains on your behalf.
The ongoing work includes reviewing access rules, applying security updates and handling changes as your business evolves.
The hardware can still belong to you. What makes it a managed service is the responsibility for operating it, with a clear agreement about what is covered and who acts when something needs attention.
Some providers deliver the same filtering from the cloud and call it firewall as a service, or FWaaS. There is no appliance in your comms cabinet, which suits businesses with staff spread across many locations.
What Exodesk’s managed firewall service includes
Six areas of work, managed around your sites, business applications and access requirements.
Your agreement sets out the included work, support hours and escalation arrangements.
Configuration and access rules
Rules built around the connections your business needs, including access between sites and networks where required.
Firmware and security updates
Vendor updates and security advisories, with a process for urgent vulnerabilities outside routine maintenance.
Monitoring
Checks on device availability, security and threat events, VPN tunnel status, and changes to configuration or firmware.
Change requests
A defined route for requesting changes. Requests come from named approvers, and each change is recorded with the business reason and who approved it.
Rule reviews
Checking whether existing access is still needed, and identifying rules that should be changed or removed, on an agreed schedule.
Backups and reporting
Configuration backed up after each change and on a schedule, held off the device, with regular reporting on the work completed.
Monitoring and response are different parts of the service. Your agreement identifies when alerts are reviewed, who responds and how urgent issues are escalated. Where you need cover outside business hours, that is set in the agreement or delivered through managed detection and response, which has its own scope.
How you know the work is being done
Ongoing management should leave a record you can ask for.
You should be able to see what was checked, what changed and what still needs attention.
Firmware and support status
Which version is running, whether the device remains supported, and what updates or exceptions are outstanding.
Rule review and change history
What access was reviewed or changed, the business reason, and who approved it.
Alerts and actions
What was investigated, what action followed, and whether anything remains unresolved.
Configuration backup status
When the latest backup succeeded, and the outcome of any restoration test performed.
A count of blocked connections is only part of the picture. The more useful questions are whether the firewall is maintained, whether its rules still match your business, and whether identified issues have been addressed.
A working internet connection does not prove the firewall is current
A firewall can keep passing traffic while its configuration falls behind.
- Access that outlived its reason. A supplier may still have a route in long after the work finished.
- Temporary rules that stayed. An exception added for one job remains because nobody removed it.
- Firmware nobody owns. Updates go unapplied because checking the vendor’s advisories is not in anyone’s job description.
None of those has to interrupt the connection, which is why they go unnoticed. The consequences are not theoretical. The NCSC published joint guidance on edge device security with the Australian, Canadian and United Kingdom agencies, which records that Five Eyes agencies have seen an increase in targeted attacks on edge devices, a category that explicitly names firewalls, routers and VPN gateways. The NCSC’s cyber threat report notes that historical vulnerabilities, some from 2019 or earlier, are still frequently exploited in New Zealand incidents even though fixes are readily available.
Regular management checks both sides: whether the business can use the systems it needs, and whether access that is no longer justified has been removed.
How we secure the firewall itself
The firewall is a security control, and it is also a target.
- Named administrator accounts, so changes can be traced to an individual
- Multi-factor authentication for management access
- Restricted access to management interfaces
- Removal of access when an administrator or supplier no longer needs it
- Logging of administrative changes
- Tracking vendor security advisories and assessing urgent action
When a vulnerability is being actively exploited, applying an update may be only part of the response. Patching closes the vulnerability. It does not, by itself, establish that an attacker has been removed from an already compromised device.
What does a managed firewall cost?
It depends on the equipment, the network and the level of management required.
We scope those requirements before quoting, including whether your existing firewall can remain. Five things move the figure:
- Equipment. Firewall capacity, supported features, and whether replacement or a paired device is needed.
- Setup and migration. Existing documentation, configuration changes, testing and cutover requirements.
- Ongoing management. Number of sites and devices, rule complexity, reviews and change requirements.
- Security subscriptions. The filtering, inspection and other licensed features selected.
- Monitoring and response. The events covered, support hours and escalation arrangements.
Your quote should make clear what is included in the recurring fee, what is charged separately and who owns the equipment. Hardware can be bought outright or included in the monthly fee, and the service can be taken on its own or as part of managed IT services.
Is managing the firewall in house an option?
Yes, if you have the skills and time to maintain it. The comparison includes updates, rule reviews, monitoring, documentation and cover when the usual administrator is unavailable. A managed service gives those tasks an agreed owner and scope.
What happens if the firewall or internet connection fails?
The recovery plan depends on which part has failed.
A second internet connection does not replace a failed firewall, and the two are often confused.
The primary internet connection fails
A backup connection, with failover configured and tested.
The firewall itself fails
A supported replacement process, or a properly configured pair of firewalls.
A configuration change causes a problem
A known working configuration and a rollback process.
Power fails
Suitable power protection for the firewall and the other equipment needed to keep connectivity working.
Where automatic internet failover is configured, connectivity can switch to the backup connection. Calls, VPNs and application sessions may still reconnect, so testing needs to include the services your business relies on. A backup business internet connection is the cheaper half of that conversation.
The right arrangement depends on how long you can operate without those services. Replacement availability, configuration recovery and any failover arrangements should be agreed before an outage.
How we take over an existing firewall
Document what is there
Identify the device, support status, firmware, licences, access rules and the systems that depend on it.
Agree the required changes
Check the purpose and usage of existing rules. Investigate undocumented access before deciding what to remove, with a rollback plan in place.
Confirm whether the equipment can stay
Assess vendor support, capacity, licensing and compatibility with the management service.
Plan and test the change
Agree the cutover window, the business checks that need to pass, and the rollback arrangements.
Start ongoing management
Establish monitoring, configuration backups, review dates and the process for future changes.
The work and the interruption depend on the existing setup. Those details are scoped before the change takes place.
Why work with Exodesk?
Supporting businesses since 1989
We support New Zealand organisations from our teams in Christchurch and Dunedin, bringing the firewall into the wider discussion about your systems, connectivity and support.
Clear responsibility for ongoing work
Your agreement identifies the work Exodesk handles and the decisions that need your approval. That gives your team a clear route for changes and issues.
Connected to the rest of your IT
Firewall management sits alongside our cyber security services and business internet support, with the wider picture of network security in view.
Managed firewall questions
Can you manage the firewall we already own?
That depends on its vendor, model, support status, capacity and licensing. We check whether it is suitable for the service before recommending that it stays or is replaced.
Does the office firewall protect staff working from home?
Only traffic routed through the office firewall receives its filtering. Remote traffic that bypasses it needs other controls. Endpoint protection, secure accounts and appropriate access controls remain necessary in either arrangement.
Does a managed firewall replace endpoint or email security?
No. A firewall controls traffic passing through it. It does not cover every action on a device, every email threat or every compromised account. It is one part of your wider security setup.
Can a firewall inspect encrypted traffic?
Its visibility depends on the device, the enabled features and the configuration. Inspecting encrypted content requires suitable decryption arrangements, which need to account for application compatibility and privacy requirements.
Who can approve firewall rule changes?
Named approvers agreed when the service starts. Each change is recorded with the business reason, who approved it and when it was applied. Urgent changes can be requested by an agreed contact and are recorded and reviewed afterwards.
What happens when an urgent security advisory is issued?
We check whether your devices are affected, apply the vendor’s guidance, and tell you if there will be any disruption. Where there are signs that a device has already been compromised, that is handled as an incident rather than as a patch.
What is a next-generation firewall?
A next-generation firewall inspects the application and content behind a connection, rather than judging it by address and port alone. That supports blocking known malicious destinations, filtering web categories and detecting intrusion attempts. Most business firewalls sold today are next-generation devices, though the features sit behind separate subscriptions.
How often should firewall firmware be updated?
On a defined schedule, with urgent security patches applied out of cycle when the vendor issues an advisory. The NCSC has reported that vulnerabilities from 2019 and earlier are still being exploited in New Zealand incidents despite fixes being available, which is a patching failure rather than a technology one.
Can a firewall stop ransomware?
It reduces the risk and cannot remove it. A firewall can block known malicious destinations and stop an infected machine calling out, which limits how far an attack spreads. It cannot stop a staff member entering credentials on a convincing fake login page, so it belongs alongside endpoint protection, multi-factor authentication and tested backups.
Does a managed firewall help with Privacy Act compliance?
In part. Information privacy principle 5 requires agencies to protect the personal information they hold with security safeguards that are reasonable in the circumstances, and a boundary control that is kept current is part of what reasonable looks like. It is one contributing control among several.
Do you provide managed firewalls outside Christchurch and Dunedin?
Yes. We support organisations throughout New Zealand, including businesses with several sites, from our teams in Christchurch and Dunedin.
Talk to us about your firewall
Tell us about your current equipment, sites and support needs. We will discuss whether your existing firewall may be suitable and what needs checking before recommending a service.
It helps to have the firewall make and model, the number of sites and any immediate concerns. If you do not have those details, start with what you know.
Discuss your firewall setup
Tell us a little about your setup and we will be in touch to arrange a time that suits.
Prefer to talk?
Christchurch
Level 1, 85 Riccarton Road
Christchurch 8011
03 343 3124
Dunedin
Level 3, Bartons Building
2 Stafford Street, Dunedin 9016
03 479 2941