A small business firewall sits between your internet circuit and everything inside the office, decides which traffic is allowed in and out, and gives remote staff a safe way back in. Size it by the throughput it can manage with its security features switched on, not by the headline number on the box, and plan for who will patch it, because an unpatched firewall is a liability. For most small offices the right answer is a business-grade next-generation firewall, set to deny by default, with someone clearly responsible for updates.
The router your carrier hands you is not a firewall in any meaningful sense. It moves packets and may do basic address translation, but it was not built to inspect traffic, separate your networks or log what happened. Here is what a proper firewall does, how to buy one without overspending, and how to decide whether to run it yourself.
What a business firewall actually does
At its simplest, a firewall keeps a table of the connections your staff start and lets the replies back in, while refusing unsolicited traffic from outside. That is called stateful inspection, and every business firewall does it. The products you will be quoted add layers on top:
- Application control. Rules based on what the traffic is (a video service, a file-sharing tool, a remote-access app) rather than only on port numbers.
- Intrusion prevention (IPS). Signatures that spot known attack patterns and drop them.
- Web and DNS filtering. Blocking categories of sites and known malicious domains.
- Encrypted traffic inspection. Decrypting and re-encrypting web traffic so the other features can see inside it. Powerful, demanding on the hardware, and something to plan carefully.
- VPN. Encrypted tunnels for remote staff and for linking offices.
- Segmentation. Separate zones for staff, guests, payment terminals, cameras and servers, with rules between them.
- Logging. A record of what was allowed and blocked, which is what you need after an incident.
A device with most of that list is usually sold as a next-generation firewall (NGFW) or, at the smaller end, as a unified threat management (UTM) appliance. The labels overlap. What matters is which features you will actually turn on.
What a firewall cannot do
It helps to be clear about the limits before you spend money:
- It cannot stop a large DDoS attack. If an attacker fills your circuit, the firewall is on the wrong side of the problem. That protection has to sit upstream in the carrier network, which we cover in DDoS protection explained.
- It does not protect laptops away from the office. Once staff work from home or a coffee shop, their traffic never touches the office box unless you force it back through a VPN. That is the problem SASE was built to address.
- It does not replace endpoint protection, backups or multi-factor sign-in. It is one layer, and attackers who steal a password walk past it.
Sizing: the number that matters
Every firewall datasheet leads with a large throughput figure. That number is usually measured with large packets and only basic stateful filtering. Turn on intrusion prevention, application control and malware scanning, and real throughput can fall to a fraction of it. Turn on encrypted traffic inspection and it often falls further.
Vendors publish these lower figures too, under names like threat protection throughput or NGFW throughput. Those are the numbers to size against. The rule of thumb we use: the firewall's throughput with your intended features enabled should comfortably exceed the speed of your circuit, with room for growth, because a firewall that cannot keep up quietly turns a fast circuit into a slow one.
Other sizing factors
- Concurrent connections and new sessions per second. Busy offices, guest Wi-Fi and phone systems open many connections at once.
- VPN throughput and tunnel count. If half the team connects from home, the encryption load is real.
- Ports and interfaces. Enough for your circuit, a backup circuit, and each zone you plan to separate.
- High availability. A second identical unit that takes over if the first fails. Worth it where the business cannot run without the internet.
A worked example
Hypothetical figures for illustration only. They are not taken from any vendor's datasheet.
A 35-person office is moving to a 500 Mbps dedicated internet circuit. It is offered a compact firewall whose datasheet lists 2 Gbps of firewall throughput, which looks generous. Further down, the same datasheet lists about 400 Mbps of threat protection throughput with intrusion prevention and malware scanning on, and less again with encrypted traffic inspection.
With the features the office actually wants, that box tops out below the circuit speed. Staff would see a 500 Mbps circuit behave like a slower one at busy times, and the office would likely blame the carrier. The next model up, rated at around 1 Gbps with protection on, covers the circuit with headroom. Spending a little more on the right box beats paying for a circuit the firewall cannot use.
A setup checklist
Most firewall problems we see are configuration, not hardware. Before the new box goes live:
- Deny inbound by default. Open only what you host, to the addresses that need it.
- Remove the old "allow any" rules. Temporary rules from a past project tend to become permanent.
- Lock down management. No admin access from the internet, multi-factor sign-in for administrators, and named accounts instead of a shared password.
- Turn on multi-factor sign-in for the VPN. A VPN protected by a password alone is a common way in.
- Separate the networks. Guests, payment terminals, cameras and staff in different zones with rules between them.
- Send logs somewhere. Keep them long enough to investigate an incident you discover weeks later.
- Set the carrier's equipment correctly. If the carrier provides a router, agree whether it runs in bridge mode or hands off a routed block, so you are not translating addresses twice.
- Plan your static IPs. A high availability pair and hosted services can need several public addresses. See static IPs and BGP for how blocks are sized.
- Back up the configuration after every change, off the device.
Patching and subscriptions: the part people forget
A firewall is not a one-time purchase. Two things keep it useful.
Firmware updates
Firewalls and VPN gateways are attractive targets because they face the internet and hold the keys to the network. Vendors publish security fixes regularly, and serious flaws in edge devices are disclosed every year across the industry. Someone needs to watch for those notices and apply updates promptly, in a maintenance window, with a way to roll back.
Security subscriptions
Intrusion signatures, web filtering lists and malware definitions usually come as a subscription. When it lapses, the box often keeps passing traffic while the protection quietly stops updating. Put the renewal date in the same calendar as your circuit contracts, and check what the device does when the licence expires. Hardware also reaches end of support, after which updates stop entirely.
Run it yourself, or have it managed
| Self-managed | Managed firewall | |
|---|---|---|
| Who writes the rules | Your IT person or contractor | The provider, from your requirements |
| Who applies updates | Whoever remembers | The provider, on a schedule |
| Monitoring | Usually none outside office hours | Often 24/7, depending on the service |
| Cost shape | Hardware plus subscriptions plus staff time | A monthly fee, sometimes with hardware included |
| Best for | Offices with capable in-house IT | Offices where nobody owns security day to day |
Self-management works well when there is a person with the time and skill to do it. It goes wrong when the firewall was set up once by a contractor who has since moved on, and nobody has logged in for two years. If that describes your office, a managed service is usually cheaper than the first incident. FiberX quotes managed next-generation firewalls and monitoring as part of our cybersecurity service, and the same team can handle the switches and Wi-Fi behind it through managed network.
If you run several sites, a firewall with built-in SD-WAN can handle both security and circuit failover in one device per site, which is simpler to manage than two boxes at every location.
Cyber insurance and client questionnaires
Insurers and larger clients increasingly send security questionnaires. Common questions include whether remote access uses multi-factor sign-in, whether systems are patched on a schedule, whether backups are kept separate from the network, and whether anyone monitors alerts. A well-run firewall helps answer several of those honestly. Answer them accurately, because a claim can turn on what you said you had in place. This is general information, not legal or insurance advice.
Questions to ask your provider
- What is the throughput with intrusion prevention, application control and encrypted inspection enabled, not just the headline figure?
- Who applies firmware updates, how quickly after a security notice, and in what window?
- What happens to traffic and protection if the subscription lapses?
- When does this hardware model reach end of support?
- Is a high availability pair included or available, and how many public IPs will it need?
- Where are logs stored, for how long, and can I get them after an incident?
- Who do I call at night when the firewall blocks something the business needs?
Getting the circuit and the firewall right together
The firewall and the circuit should be sized as a pair: a fast line behind an undersized box wastes money, and a large box on a slow line is overkill. When several carriers bid on your address, we can price the circuit, a backup and the managed security on the same quote, so you see the whole cost at once. The carrier pays FiberX, so there is no markup, and our lowest-price promise applies to qualified like-for-like quotes. It is free, with no obligation, and you usually hear back the same day. Send us your address, call 478-758-8091 or text (347) 870-0965, and see how quotes work on our pricing page.