Network Design & Resilience

A Small Business Firewall Guide: What to Buy, How to Size It, and Who Should Run It

The box under the desk decides more about your security than the circuit above it. Here is how to pick one that fits, and how to keep it from going stale.

A small business firewall sits between your internet circuit and everything inside the office, decides which traffic is allowed in and out, and gives remote staff a safe way back in. Size it by the throughput it can manage with its security features switched on, not by the headline number on the box, and plan for who will patch it, because an unpatched firewall is a liability. For most small offices the right answer is a business-grade next-generation firewall, set to deny by default, with someone clearly responsible for updates.

The router your carrier hands you is not a firewall in any meaningful sense. It moves packets and may do basic address translation, but it was not built to inspect traffic, separate your networks or log what happened. Here is what a proper firewall does, how to buy one without overspending, and how to decide whether to run it yourself.

What a business firewall actually does

At its simplest, a firewall keeps a table of the connections your staff start and lets the replies back in, while refusing unsolicited traffic from outside. That is called stateful inspection, and every business firewall does it. The products you will be quoted add layers on top:

  • Application control. Rules based on what the traffic is (a video service, a file-sharing tool, a remote-access app) rather than only on port numbers.
  • Intrusion prevention (IPS). Signatures that spot known attack patterns and drop them.
  • Web and DNS filtering. Blocking categories of sites and known malicious domains.
  • Encrypted traffic inspection. Decrypting and re-encrypting web traffic so the other features can see inside it. Powerful, demanding on the hardware, and something to plan carefully.
  • VPN. Encrypted tunnels for remote staff and for linking offices.
  • Segmentation. Separate zones for staff, guests, payment terminals, cameras and servers, with rules between them.
  • Logging. A record of what was allowed and blocked, which is what you need after an incident.

A device with most of that list is usually sold as a next-generation firewall (NGFW) or, at the smaller end, as a unified threat management (UTM) appliance. The labels overlap. What matters is which features you will actually turn on.

What a firewall cannot do

It helps to be clear about the limits before you spend money:

  • It cannot stop a large DDoS attack. If an attacker fills your circuit, the firewall is on the wrong side of the problem. That protection has to sit upstream in the carrier network, which we cover in DDoS protection explained.
  • It does not protect laptops away from the office. Once staff work from home or a coffee shop, their traffic never touches the office box unless you force it back through a VPN. That is the problem SASE was built to address.
  • It does not replace endpoint protection, backups or multi-factor sign-in. It is one layer, and attackers who steal a password walk past it.

Sizing: the number that matters

Every firewall datasheet leads with a large throughput figure. That number is usually measured with large packets and only basic stateful filtering. Turn on intrusion prevention, application control and malware scanning, and real throughput can fall to a fraction of it. Turn on encrypted traffic inspection and it often falls further.

Vendors publish these lower figures too, under names like threat protection throughput or NGFW throughput. Those are the numbers to size against. The rule of thumb we use: the firewall's throughput with your intended features enabled should comfortably exceed the speed of your circuit, with room for growth, because a firewall that cannot keep up quietly turns a fast circuit into a slow one.

Other sizing factors

  • Concurrent connections and new sessions per second. Busy offices, guest Wi-Fi and phone systems open many connections at once.
  • VPN throughput and tunnel count. If half the team connects from home, the encryption load is real.
  • Ports and interfaces. Enough for your circuit, a backup circuit, and each zone you plan to separate.
  • High availability. A second identical unit that takes over if the first fails. Worth it where the business cannot run without the internet.

A worked example

Hypothetical figures for illustration only. They are not taken from any vendor's datasheet.

A 35-person office is moving to a 500 Mbps dedicated internet circuit. It is offered a compact firewall whose datasheet lists 2 Gbps of firewall throughput, which looks generous. Further down, the same datasheet lists about 400 Mbps of threat protection throughput with intrusion prevention and malware scanning on, and less again with encrypted traffic inspection.

With the features the office actually wants, that box tops out below the circuit speed. Staff would see a 500 Mbps circuit behave like a slower one at busy times, and the office would likely blame the carrier. The next model up, rated at around 1 Gbps with protection on, covers the circuit with headroom. Spending a little more on the right box beats paying for a circuit the firewall cannot use.

A setup checklist

Most firewall problems we see are configuration, not hardware. Before the new box goes live:

  • Deny inbound by default. Open only what you host, to the addresses that need it.
  • Remove the old "allow any" rules. Temporary rules from a past project tend to become permanent.
  • Lock down management. No admin access from the internet, multi-factor sign-in for administrators, and named accounts instead of a shared password.
  • Turn on multi-factor sign-in for the VPN. A VPN protected by a password alone is a common way in.
  • Separate the networks. Guests, payment terminals, cameras and staff in different zones with rules between them.
  • Send logs somewhere. Keep them long enough to investigate an incident you discover weeks later.
  • Set the carrier's equipment correctly. If the carrier provides a router, agree whether it runs in bridge mode or hands off a routed block, so you are not translating addresses twice.
  • Plan your static IPs. A high availability pair and hosted services can need several public addresses. See static IPs and BGP for how blocks are sized.
  • Back up the configuration after every change, off the device.

Patching and subscriptions: the part people forget

A firewall is not a one-time purchase. Two things keep it useful.

Firmware updates

Firewalls and VPN gateways are attractive targets because they face the internet and hold the keys to the network. Vendors publish security fixes regularly, and serious flaws in edge devices are disclosed every year across the industry. Someone needs to watch for those notices and apply updates promptly, in a maintenance window, with a way to roll back.

Security subscriptions

Intrusion signatures, web filtering lists and malware definitions usually come as a subscription. When it lapses, the box often keeps passing traffic while the protection quietly stops updating. Put the renewal date in the same calendar as your circuit contracts, and check what the device does when the licence expires. Hardware also reaches end of support, after which updates stop entirely.

Run it yourself, or have it managed

Self-managedManaged firewall
Who writes the rulesYour IT person or contractorThe provider, from your requirements
Who applies updatesWhoever remembersThe provider, on a schedule
MonitoringUsually none outside office hoursOften 24/7, depending on the service
Cost shapeHardware plus subscriptions plus staff timeA monthly fee, sometimes with hardware included
Best forOffices with capable in-house ITOffices where nobody owns security day to day

Self-management works well when there is a person with the time and skill to do it. It goes wrong when the firewall was set up once by a contractor who has since moved on, and nobody has logged in for two years. If that describes your office, a managed service is usually cheaper than the first incident. FiberX quotes managed next-generation firewalls and monitoring as part of our cybersecurity service, and the same team can handle the switches and Wi-Fi behind it through managed network.

If you run several sites, a firewall with built-in SD-WAN can handle both security and circuit failover in one device per site, which is simpler to manage than two boxes at every location.

Cyber insurance and client questionnaires

Insurers and larger clients increasingly send security questionnaires. Common questions include whether remote access uses multi-factor sign-in, whether systems are patched on a schedule, whether backups are kept separate from the network, and whether anyone monitors alerts. A well-run firewall helps answer several of those honestly. Answer them accurately, because a claim can turn on what you said you had in place. This is general information, not legal or insurance advice.

Questions to ask your provider

  • What is the throughput with intrusion prevention, application control and encrypted inspection enabled, not just the headline figure?
  • Who applies firmware updates, how quickly after a security notice, and in what window?
  • What happens to traffic and protection if the subscription lapses?
  • When does this hardware model reach end of support?
  • Is a high availability pair included or available, and how many public IPs will it need?
  • Where are logs stored, for how long, and can I get them after an incident?
  • Who do I call at night when the firewall blocks something the business needs?

Getting the circuit and the firewall right together

The firewall and the circuit should be sized as a pair: a fast line behind an undersized box wastes money, and a large box on a slow line is overkill. When several carriers bid on your address, we can price the circuit, a backup and the managed security on the same quote, so you see the whole cost at once. The carrier pays FiberX, so there is no markup, and our lowest-price promise applies to qualified like-for-like quotes. It is free, with no obligation, and you usually hear back the same day. Send us your address, call 478-758-8091 or text (347) 870-0965, and see how quotes work on our pricing page.

// QUESTIONS

Frequently Asked Questions

01Does a small business need a firewall if the carrier provides a router?

Usually yes. A carrier router moves traffic and may block unsolicited connections, but it is not designed to separate networks, inspect traffic, run a secure VPN or keep useful logs. A business-grade firewall behind it does those jobs.

02How do I size a firewall for my internet speed?

Use the throughput figure the vendor publishes with security features enabled, often called threat protection or NGFW throughput, rather than the headline firewall throughput. That figure should comfortably exceed your circuit speed, with room for growth and for VPN traffic.

03What is the difference between a UTM and a next-generation firewall?

The terms overlap. Both combine stateful filtering with features such as intrusion prevention, web filtering and VPN. UTM is more often used for smaller all-in-one appliances, while NGFW stresses application awareness. Compare the features you will actually enable and the throughput with them on.

04What happens when a firewall subscription expires?

It depends on the vendor. Often the device keeps passing traffic while intrusion signatures, web filtering lists and malware definitions stop updating, so protection weakens without any obvious sign. Check the behaviour before you buy and track the renewal date.

05Can a firewall stop a DDoS attack?

Not a large one. A volumetric attack fills the circuit before traffic reaches the firewall. Protection against that has to sit upstream, in the carrier network or a scrubbing service.

06Is a managed firewall worth it for a small office?

It is worth it when nobody in the business owns the firewall day to day. A managed service handles rules, updates and monitoring for a monthly fee. If you have capable in-house IT with time to patch and review logs, self-management can work well.

// FREE · NO OBLIGATION · SAME-DAY RESPONSE

Want This Priced for Your Address?

Reading is cheap; a real number for your building is better. Pick a time below, or call and we will talk it through.

EMAIL INFO@FIBERXINTERNET.COM · TEXT (347) 870-0965

FIBERX · APPOINTMENT CONSOLE
Book an Appointment

Talk to Phil. Pick a Time.

A quick call with your dedicated agent — internet quotes, AI automation, or both. No obligation, same-day response.

Pick your 30-minute slot ALL TIMES ET
or call 478-758-8091

REQUEST GOES STRAIGHT TO PHIL · SAME-DAY CONFIRMATION