Cybersecurity

Firewall Installation and Consulting

Installing a firewall is more than racking the box and getting the internet working. We set up firewalls that know which traffic passes and why, split the network into sensible zones and keep the management interface locked down, and we apply the same thinking to the device you already have.

CybUP TeamLast updated: 7 min read

In short

Firewall installation and consulting covers choosing the right firewall for your company, installing it, writing and cleaning up its rules, segmenting the network with VLANs, hardening the device and maintaining it afterwards. CybUp is vendor-neutral: we carry out new installations, configuration reviews and rule optimisation on FortiGate, pfSense, MikroTik and similar devices.

What does firewall consulting cover?

Firewall consulting covers the whole life of a firewall, from choosing the right device to keeping the rules in order years later. For a company opening a new office it means a needs assessment and a firewall installation from scratch. For a company that has run the same device for years it means reviewing the existing firewall configuration, clearing out redundant rules and closing gaps.

Some firewall installers are tied to one vendor and answer every question with the same box. We are vendor-neutral. The choice comes down to your user count, internet lines, branch layout, remote access needs and how much your team can realistically manage.

  • Needs assessment and vendor/model selection
  • New installation or migration from an existing device
  • Firewall rule review and rule optimisation
  • VLAN-based segmentation and guest network separation
  • Hardening of management access and firmware
  • Logging, monitoring and scheduled maintenance

Which firewall should I buy?

The short answer: one that meets your needs and that your team can actually manage. A few typical cases make this clearer.

Companies with several branches that want security services such as IPS, web filtering and application control in one interface often choose FortiGate; those security services come as an annual subscription. If you want flexibility, an open-source base and a free hand in choosing hardware, pfSense is a strong option. In small offices and branches, MikroTik devices handle routing and basic firewalling economically, although they take more know-how to configure. Sophos, Palo Alto and Check Point are also on the table, each with its own strengths.

When sizing a model, ignore the headline “firewall throughput” figure on the datasheet and look at the figure with IPS and SSL inspection switched on. Once those services are enabled, real capacity drops noticeably. We work through these numbers with you at the selection stage and give a reasoned recommendation as part of the free review.

How do you configure a firewall properly?

A sound firewall configuration starts from default deny: only the traffic you need is allowed and everything else is dropped. Netgate’s firewall rule best practices for pfSense recommend the same approach, and the principle holds for every vendor.

In practice every rule has a source, a destination, a service and a description. Instead of an “anything from LAN to anywhere” rule, the user network gets the ports for web, email and business applications, and servers are reachable only on the ports they need. Every service exposed to the outside (VPN, web server, remote desktop) has to justify itself. We do not recommend exposing RDP directly to the internet; remote access goes through a VPN.

The last step of an installation is documentation. At handover you keep the rule table, address objects, VLAN plan and management access details in writing. If another team takes over tomorrow, they should be able to see what is open and why.

“A default deny strategy for firewall rules is the best practice. Firewall administrators should configure rules to permit only the bare minimum required traffic for the needs of a network, and let the remaining traffic drop with the default deny rule built into pfSense® software.”

— Netgate pfSense documentation — Firewall Rule Best Practices

Why do firewall rules need reviewing and optimising?

Because firewall rules pile up and nobody deletes them. A port opened for a project stays open after the project ends; an old server’s IP is handed to a new device and the old rule still lets traffic through to it. The pfSense documentation illustrates this with the “we removed that server six months ago” example and recommends reviewing rules at regular intervals.

Take a distribution company with 120 users and three branches. Over four years nearly 300 rules have built up on its FortiGate. Some get no traffic at all, some never match because a broader rule above them shadows them, and a few are “any-any”. A rule review starts with hit counters and logs. Unused rules are disabled first, watched for a while and only then deleted. Broad rules are narrowed and similar rules are merged with address and service groups. The result is a shorter rule table that is easier to read and to audit.

“The shorter a ruleset, the easier it is to manage. Long rulesets are difficult to work with, increase the chances of human error, tend to become overly permissive, and are significantly more difficult to audit.”

— Netgate pfSense documentation — Firewall Rule Best Practices

How does network segmentation improve firewall security?

Segmentation stops an attacker who compromises one device from spreading across the whole network. Users, servers, guest Wi-Fi, IP cameras, printers and management interfaces go into separate VLANs, and traffic between them is controlled by firewall rules.

The Personal Data Security Guide issued under KVKK, Türkiye’s Personal Data Protection Law (Law No. 6698), also gives restricting access between network components, or separating them, as an example measure where personal data is processed. An accounting or HR server sitting in the same broadcast domain as the guest network is, from this point of view, an easy gap to fix.

What does firewall hardening involve?

The firewall is a target in its own right; critical vulnerabilities are published from time to time in the management and SSL VPN interfaces of security appliances. Hardening starts by shutting off internet access to the management interface, so the device is managed only from specific IPs or a separate management VLAN. The default admin account is disabled, and named personal accounts are used instead, with two-factor authentication where possible.

Unused services are switched off, firmware is upgraded to the vendor’s recommended stable release and one person is made responsible for tracking updates. On MikroTik this means allowing access to the device only from the LAN in the RouterOS input chain; on FortiGate the same result comes from local-in policies and trusted hosts. For a fuller checklist, the CIS Benchmarks provide reference configurations for most vendors.

What does a firewall security audit check?

Our audit is a configuration review of your existing device; it is not a certified compliance audit or a penetration test. We go through the rule table, NAT and port forwarding, VPN settings, management access, firmware version, logging and backup status one by one.

You end up with a list of findings ranked by risk and a recommended change for each. If you prefer, we apply the changes during a maintenance window. Pairing the review with a vulnerability scan of your external surface gives a definite answer to “is the port we think is closed actually closed?”

What is included in firewall maintenance and support?

A firewall needs regular maintenance after installation. That means planned firmware updates, configuration backups, tracking licence and subscription expiry dates, applying new rule requests through change records and reviewing the rule table at set intervals.

Collecting logs in one place and spotting anything unusual is part of maintenance too. Events such as a line outage, high CPU load or a VPN tunnel dropping can be fed into Zabbix monitoring. We work on site at offices in Istanbul and remotely everywhere else in Türkiye.

What you receive

  • A reasoned vendor and model recommendation (for new installations)
  • An installed, hardened firewall running the current stable firmware
  • Annotated rule table, VLAN and IP plan
  • Configuration review report and findings list for existing devices
  • Before/after comparison of the rule optimisation
  • Configuration backup and management access document

How we work

  1. 1

    Free review

    We talk through your network, your current device and your requirements, review an export of the existing configuration and send a written quote.

  2. 2

    Design

    The rule logic, VLAN plan, remote access method and management access are agreed on paper and sent for your approval.

  3. 3

    Installation or clean-up

    The new device is configured or the existing rules are reworked; cutover happens in a maintenance window that does not interrupt work.

  4. 4

    Testing and verification

    User and server access is tested, and the external IPs are scanned to confirm that only the planned services are open.

  5. 5

    Documentation and maintenance

    Documentation is handed over; if you wish, periodic maintenance and rule reviews are scheduled.

Frequently asked questions

What does firewall consulting include?

It covers needs assessment and device selection, installation, writing and cleaning up rules, segmentation, hardening, logging and periodic maintenance. Depending on what you need, a review of the existing configuration can also be a consulting engagement on its own.

Which firewall brand should we choose?

It depends on your user count, branch layout, the security services you want and who will manage the device. FortiGate, pfSense, MikroTik and Sophos each have scenarios where they fit. In the free review we listen to your requirements and give a reasoned recommendation.

Can you clean up our existing firewall without replacing it?

Yes. If your device is still within vendor support and has enough capacity, there is no need to buy a new one. We carry out rule optimisation, hardening and segmentation on the existing device.

Will the internet go down during installation?

There is a short outage at the moment of cutover. We schedule it outside working hours or at the weekend and work with a quick rollback plan to the old configuration. Rule clean-up work can usually be done without any downtime.

Does a firewall security audit replace a formal audit?

No. What we do is a configuration review that produces a technical findings report. When a certified audit or a penetration test report is required, that work is carried out by authorised organisations; our report can be used to prepare for it.

Do you work remotely?

Yes. Reviews, rule clean-ups and maintenance are done over secure remote access anywhere in Türkiye. For installations that involve mounting new hardware or cabling we work on site in Istanbul; for other cities we can ship a pre-configured device and bring it into service remotely.

Do we need a firewall maintenance and support contract?

It is not mandatory, but we recommend it. Critical vulnerabilities in security appliances are published regularly, and a missed firmware update is a direct risk. Maintenance covers updates, backups, licence tracking and periodic rule reviews.

How is the price worked out?

It depends on the number of devices and branches, the size of the current rule table and whether the job is a new installation or a clean-up. We send a written quote after reviewing the scope; the review is free.

Sources and official documentation

CybUP Team

Written and reviewed by the CybUP technical team in Istanbul. Last updated: 10 October 2026.

Request a free review for this service

Fill in the form and we will get back to you as soon as possible. For urgent matters, WhatsApp or phone is faster.

Message on WhatsApp

Cookie preferences

Strictly necessary

Required for the core functions of the site and to remember your choices. Cannot be turned off.

Analytics

Lets us measure which pages are visited, anonymously (Google Analytics via Google Tag Manager).

Marketing

Used for advertising measurement and personalisation.