Business firewall: why your internet provider’s router isn’t a lock

The box your internet provider left behind was built to connect you, not to guard you.

Every file, email and payment in your office passes through one front door. A business firewall decides what gets in and out, spots suspicious traffic and stops it. We use Cisco Meraki MX with Advanced Security. Here’s why, and how we set it up.

What is a business firewall?

A firewall sits between your office network and the internet and checks traffic against rules. A business firewall goes further than a basic router: it can recognise known attack patterns and block them (IDS and IPS), block malicious files and websites, split your network into separate zones (VLANs), connect offices securely, and send alerts and logs to the people looking after it.

1 Gbpsthe speed we size for, with IDS and IPS switched on, so protection doesn’t throttle your internet
40M+security events analyzed every month across our stack
24/7monitoring, with email and SMS alerts to our team

Why it matters

If you own the business

  • It’s the lock on the front door. Everything else in the office sits behind it.
  • Guests stay off your network. A visitor’s phone shouldn’t sit next to your server and your client files.
  • Multiple sites, one network. Offices, clinics or yards can be linked securely, so staff work the same way in each place.

If you run the office

  • Someone else watches it. Alerts go to our team, not to a box blinking in a closet.
  • The internet doesn’t get slower. We size the firewall to your connection so the protection stays switched on.
  • One call when it’s weird. Slow internet, a site that won’t load, Wi-Fi trouble: call (604) 813-7881 and a person picks up.

Internet provider router vs business firewall

A typical internet provider router

  • Shares one internet connection with everyone (NAT) and blocks unsolicited traffic coming in.
  • Usually no intrusion detection or prevention, and no malware or content filtering.
  • Limited or no support for separate networks (VLANs) beyond a basic guest Wi-Fi name.
  • Little or no logging or alerting, and firmware updates may be up to the provider.

A business firewall like Meraki MX with Advanced Security

  • Stateful firewall rules for traffic in and out.
  • IDS spots suspicious traffic. IPS stops it.
  • Malware protection and content filtering, using Cisco Talos threat intelligence.
  • VLANs to keep guests, phones, cameras and office computers apart.
  • Secure site-to-site VPN between locations.
  • Managed from the cloud, with alerts, logs and firmware updates we schedule.

A separate Wi-Fi name isn’t a separate network

Many offices give guests their own Wi-Fi name and assume they can’t reach anything important. A Wi-Fi name only changes what shows on a phone’s screen. What really separates them is a VLAN, a virtual wall inside your network. We give guest Wi-Fi its own VLAN and its own address pool (DHCP), so guests get the internet and nothing else.

How we set it up

  1. Cisco Meraki MX with Advanced Security, sized to your internet speed with IDS and IPS switched on.
  2. Separate VLANs for guests and for office devices, with guest Wi-Fi kept away from office computers and the server.
  3. A Layer 3 switch routes fast traffic between internal networks, so the firewall isn’t the bottleneck inside the office.
  4. Remote desktop is never exposed to the internet. Remote access goes through secure methods with multi-factor sign in.
  5. DNS filtering alongside the firewall, so known bad sites are blocked at lookup. How DNS filtering works
  6. Firmware updates planned around your hours, and licences tracked so protection doesn’t lapse.

What a firewall can’t do on its own

A firewall can’t stop someone typing their password into a fake sign-in page, and it can’t see much inside traffic on laptops working from home. That’s why we layer it with multi-factor sign in, DNS filtering, monitoring on every computer with Huntress alongside us, security awareness training and immutable backups.

Common mistakes we see

  1. The internet provider’s router as the only protection, with the default admin password still set.
  2. Port forwarding for remote desktop, leaving a server open to password guessing from the whole internet.
  3. Guests, cameras and office computers on one flat network.
  4. A firewall too small for the connection, so someone switches the security features off to get the speed back.
  5. Expired licences and firmware years out of date. On subscription firewalls, a lapsed licence can switch off protection or the device itself.

Firewall questions

Isn’t the router from our internet provider a firewall?

It does basic filtering, which is better than nothing. It usually doesn’t detect or stop attacks, filter malware, separate networks properly or alert anyone. A business firewall does.

What do IDS and IPS mean?

An intrusion detection system (IDS) spots traffic that matches known attack patterns. An intrusion prevention system (IPS) blocks it. On a Meraki MX they’re part of Advanced Security.

Will it slow down our internet?

Not if it’s sized right. We match the firewall to your connection, up to 1 Gbps with IDS and IPS switched on, so you don’t have to choose between speed and safety.

Do we still need antivirus?

Yes. The firewall guards the door. Protection on each computer guards what’s inside, including laptops away from the office.

Can you connect our two locations?

Yes. Meraki MX firewalls can link sites with a secure site-to-site VPN. For a plant or yard network, see manufacturing IT.

Not sure what’s guarding your front door?

Ask us to take a look. Call if something is wrong now, or book a free IT review. No pressure, no jargon.