The Challenge
- Firewall past end-of-life with firmware no longer receiving security updates
- Flat network where guest Wi-Fi, VoIP, and business systems shared one broadcast domain
- Remote-access VPN with no MFA and an outdated password policy
- No central visibility when a workstation showed signs of compromise
Environment
- End-of-life firewall appliance
- Flat LAN with mixed staff, VoIP, and guest traffic
- Microsoft 365 identity available for MFA
- Mixed endpoint protection coverage
Assessment
- Reviewed firewall rules, logs, and VPN usage patterns
- Mapped existing VLAN structure and switch port assignments
- Reviewed endpoint protection coverage and identified unmanaged devices
- Sized appropriate business-grade firewall and centrally managed endpoint (EDR) licensing for the environment
The Solution
- Deployed a business-grade firewall appliance with a documented rule set
- Implemented segmented VLANs for staff, VoIP, IoT, guest Wi-Fi, and management
- Replaced legacy VPN with a modern remote-access client and MFA via Microsoft 365
- Rolled out centrally managed endpoint protection (EDR) with firewall/endpoint synchronization enabled
- Documented the design, including network diagrams and change-control procedures
- Established an ongoing firewall health and rule-review cadence
Results
Supported, patchable firewall platform replacing the end-of-life appliance.
Segmented VLANs replaced a single flat broadcast domain.
Remote access moved onto MFA-protected VPN with modern identity controls.
Synchronized endpoint and firewall telemetry consolidated in a single management console.
Technologies Used
- Business-grade firewall
- Centrally managed endpoint protection (EDR)
- Microsoft 365 MFA
- Managed switching
Supported technologies in this project
See what we support around each platform on our supported technologies hub.
