Security & surveillance
Firewalls and VPNs: what goes out matters more than what comes in
What arrives unrequested is already blocked by any router. The useful half is the other one, and it is the half nobody configures.
A firewall is sold with an image: a wall stopping what comes from outside. That image describes a problem your router already solves, and it hides the half of the subject that genuinely matters.
What arrives from outside unrequested does not reach your machines. That is the normal behaviour of any business router and has been for a very long time, and it does not need buying a second time.
What matters is the other direction: what leaves your premises. Because on the day a machine is compromised — by an attachment, by a memory stick, by software installed on a Friday — it does its damage on the way out.
This article handles that direction, the fact that remote access is this line’s real purchase, and a local reality the catalogues do not write: a firewall’s value lives in its subscriptions, and on the day they lapse nothing changes on screen.
What comes in unrequested is already blocked
The problem that is not one has to be taken off the table first, because it occupies half the sales conversations on this line.
A business router, including your operator’s, does not pass an inbound connection nobody asked for. That is its normal operation, not a security option, and it is enough to dismiss the whole of the automated scanning that runs across the internet continuously.
So what crosses that barrier is never an inbound connection: it is something somebody at your premises went and fetched. A page opened, an attachment downloaded, software installed, a file received in a conversation.
There is one exception and it deserves naming because it is frequent: the services you deliberately opened outwards. A camera viewable remotely, a recorder, a server reachable from home, a maintenance access opened by a supplier three years ago.
Those openings are a small business’s only real inbound risk, and they are not handled by buying a firewall: they are handled by listing what is open and closing what no longer has a reason to be. That is an afternoon, and it should precede any spending on this page.
What goes out is the half nobody configures
The useful direction is outbound, and it is the part that almost always stays at its factory value: everything permitted.
The reason is understandable. Restricting outbound traffic breaks things, and it breaks them on the day of configuration, in front of people who are working. Nobody wants to start there, and nobody picks it up afterwards.
What that lets through is precisely what does the damage. A compromised machine contacts the outside to receive instructions or to send data; software encrypting shared files does it from the inside, with a legitimate employee’s rights; and data leaving looks, in a log, like somebody sending a large file.
The reasonable configuration for a twenty-person business is not to close everything. It is to restrict three categories only: administrative protocols with no reason to go out, destinations no activity in the building uses, and outbound mail sent by anything other than your mail server.
The third is worth its hour of work. A machine sending mail directly, without going through the company mailbox, is almost always a compromised machine, and it is one of the few genuinely reliable signals this equipment can produce.
Where the separations become real
The network article asks for three separations — guests, surveillance, payment — and describes them as a switch configuration. This page is where they stop being labels.
Separating without filtering does almost nothing. Two distinct networks that can nonetheless reach each other in full are two networks with a decorative boundary, and it is the arrangement we find in most installations that call themselves segmented.
What makes the separation real is a small number of written rules between those zones: the cameras talk to the recorder and to nothing else; the guest network goes out to the internet and sees no internal machine; payment reaches two specific destinations and no more.
Those three rules are few, each is tested in ten minutes, and they cover the substance of what a firewall genuinely brings a business of this size. The rest of the catalogue is optional beside them.
The check that counts is a test rather than a screenshot: from a machine on the guest network, try to reach an internal share. If you get there, the separation does not exist, whatever the colour of the diagram you were handed.
Remote access is the real purchase
In most businesses we equip, the real reason to buy a firewall is not protection: it is the tunnel. Somebody has to work from home, a second site has to join the first, or a supplier has to work without travelling.
It is a useful function, this equipment does it well, and it is the only one on this page that produces a visible benefit every day rather than a hypothetical one.
It has a counterpart that has to be stated plainly: a tunnel extends your network to a machine you do not control. An employee’s family computer, with its software, its other users and its uncertain updates, becomes for the duration of the connection a machine on your network.
Two rules limit that effect without removing the service. The first is not to grant full access: a tunnel gives access to what the person needs — a share, an application, a server — and not to the whole network.
The second is a second verification at connection, as on a mailbox. A username and a password are enough to open a tunnel, and a password turns up in some other service’s leak: that is the commonest scenario, and the second verification is what makes it inoperative.
A shared account cancels the tunnel
This section is deliberately the same as the one on shared badges in the access control article, because the mechanism is identical and it does not correct technically.
A shared remote access appears the same way: an "office" or "admin" account created to move quickly, used by three people, passed to a supplier for one visit, and never changed afterwards.
The consequences are the same, transposed. Revocation becomes impossible without cutting everybody off. The log becomes false, which is worse than absent on the day it matters who was connected. And the password circulates in messages, which puts it permanently outside your control.
The supplier case deserves detail because it is the commonest: an access created for a two-day job, still active four years later, with a password known to several people at a third party whose staff turnover you know nothing about.
The correction is the whole pillar’s: one account per person, an end date on temporary access, and a review of the list at the same moment as the access list in the audit article. The firewall does nothing for you here, and that is why the section exists.
The lapsed subscription: a router with a logo
Here is this line’s economic particularity, and it is rarely explained at purchase: a business firewall is sold with a subscription, and most of what it does beyond a router depends on that subscription.
What the subscription funds is continuous updating of what the equipment recognises: lists of malicious destinations, signatures, site categories. Without it, the equipment keeps applying your rules — so it stays useful — but it stops learning.
The problem is that on screen nothing changes. No visible alert, no indicator, no function that stops. It is exactly the mechanism of a system’s end of support, described in the server article: the machine works, and it has stopped being protected by what made it special.
That point is made worse locally by how it is paid. A renewal billed in foreign currency, on an account abroad, with the difficulties the hosting article describes, is a renewal that slips a quarter, then a year, then stops happening.
The consequence is an honest purchasing decision: if you are not certain of being able to renew the subscription each year, buy the equipment for what it will do without one — the separations and the tunnel — and pay accordingly. High-end equipment without a subscription costs a lot to do a mid-range device’s job.
The rules have to fit on one page
The constraint is the switch page’s, and it is even more necessary here because firewall rules get added and never removed.
The accumulation mechanism is always the same: an application does not work, somebody adds a rule to unblock it, the application is replaced two years later, and the rule stays. After five years, a small business firewall contains fifteen or so rules nobody can say the purpose of.
That is not an aesthetic problem. A rule whose use is unknown cannot be removed, because nobody knows what will break — and a rule left there that is too broad silently cancels section 2’s separations.
The discipline that avoids it sits in two habits. Every rule carries a comment line saying who asked for it, why, and when. And every rule created for a temporary need carries an end date, exactly like section 4’s accesses.
Then an annual hour of review: read the rules, remove the ones whose reason has gone, and check that the page still fits on a page. It is the same appointment the family article requires for any measure needing a habit.
What a firewall does not see
A technical limit has to be stated that changes this equipment’s real value, and it is almost never said at the point of sale: most of what travels today is encrypted, and a firewall does not see what is inside it.
It sees who talks to whom, when, and how much. That is already useful — it is what makes section 1’s rules and section 2’s separations possible — but it does not allow anybody to say what a file contains or what a page displays.
A function exists that allows looking inside, by opening and reclosing communications in passing. It works technically and we advise against it in a business of this size, for three reasons we would rather write than leave out.
It places the equipment in the middle of everything your employees do, including their personal communications and their banking, which is a responsibility nobody in a small organisation wants to carry. It regularly breaks applications that verify their own counterparties. And it demands constant upkeep, which is exactly the kind of measure the family article classes as failing within three months.
The consequence is a realistic expectation to form before buying: a firewall gives you control over paths, not over contents. What protects against contents is on the machine, and that is section 9.
Content filtering, and why we advise against it
The function directors like most in this range is site filtering: blocking categories, preventing certain uses, measuring time spent. Why we advise against it deserves explaining rather than refusing without reason.
The first reason is that it misses. Every employee’s personal phone is in their pocket, on a network you do not control, doing everything the filter forbids. What is blocked on the machine happens on the phone, and the only measurable effect is the move.
The second is that it produces false positives costing real time: a business site classed in the wrong category, a work tool blocked, a supplier’s page unreachable. Each of those becomes a support request, and support opens an exception — see section 6.
The third is fundamental: it is a management measure dressed as a security measure, and teams receive it as such. If the subject is working time, it is handled with people; if it is security, category filtering is not what improves it.
What we do agree to configure is narrow and defensible: blocking destinations known to distribute malicious software, which is a technical list rather than a judgement about use. That is the part of filtering that protects, and it is the part that depends on section 5’s subscription.
A firewall does not replace the machine
The last limit is the most important for deciding an order of spending, and it follows from everything above: what happens to a small business happens on a machine, and the firewall is not on the machine.
An attachment opened, software installed, a memory stick plugged in, a password given on the phone: in all four cases the firewall sees a legitimate machine doing a legitimate thing. It has nothing to block because nothing looks abnormal at the moment it happens.
What handles those cases is on the machine: a system still receiving its fixes, as the server article explains; the user’s account without administrative rights; and the protection built into the system, which is today sufficient for the great majority of business machines.
That last sentence deserves writing clearly because it contradicts a habitual expense: in most cases we see, adding a second security package alongside the system’s own brings nothing measurable and slows the machine down, as the support article describes.
The order that follows is the family article’s and it does not change: the tested restore, the closed accesses, the three habits, then the products — and among the products, what is on the machine before what is in the cabinet.
What to obtain with the equipment
Four things, asked for at order time, and the first decides your independence.
Administrative access in your name and the configuration exported, in the same folder as the pillar’s other equipment. A firewall configured by a supplier whose access you do not hold is equipment you can neither check nor have taken over.
Section 6’s rules page, dated, with who asked for each rule and why. It is the document that makes an annual review possible, and without it the review does not happen.
The subscription’s expiry date, written down, and what exactly stops working on that date. That is section 5, and it belongs in your forward budget the same way a system’s end of support does.
Finally, the list of outward openings existing after installation — every service reachable from the internet, with its reason. That is section 1’s list, and it is the one we systematically find longer than the client believes.
What we do, and what we will refuse to do
What we will refuse: selling a firewall as protection against what comes from outside without saying that direction is already handled. It is this line’s most effective sales argument and it describes a solved problem.
We will refuse to configure inspection of encrypted traffic in a business of this size, and we will refuse category-based use filtering. We configure blocking of malicious destinations, which is a technical list, and we say no to the rest.
We will refuse to create remote access shared between several people or handed to a supplier without an end date, even when it would save everybody a day.
What we do: the list of existing openings drawn up and reduced before any purchase; the three outbound rules that are worth their hour, including mail sent outside your mailbox; the separations tested from the guest network rather than shown on a diagram; one remote account per person with a second verification; every rule commented and dated; and the subscription expiry written into your budget.
And what you can do this week without us: ask for the list of your company’s services reachable from the internet, and the reason for each. Then connect a machine to the guest network and try to open an internal share. Those two acts say more about your firewall than its spec sheet.
Frequently asked questions
Does a firewall protect against attacks from the internet?
That direction is already handled: a router does not pass an inbound connection nobody asked for. The real inbound risk comes from services you deliberately opened — a camera, a recorder, a forgotten maintenance access.
What should be configured first?
Outbound, which almost always stays at its factory value. Three restrictions are worth their hour: administrative protocols, destinations no activity uses, and mail sent by anything other than your mailbox — that last signals a compromised machine.
Why buy a firewall in a small business?
Usually for remote access and to make the separations described in the network article real. Separating without filtering does almost nothing: the boundary stays decorative until a few rules enforce it.
What happens when the subscription lapses?
Nothing visible, which is the problem. The equipment keeps applying your rules but stops learning. Put the expiry date in your budget, and if renewal is uncertain, buy for what the equipment will do without it.
Should encrypted traffic be inspected?
We advise against it at this size: it places the equipment in the middle of your employees’ personal communications, breaks applications, and demands constant upkeep. A firewall gives control over paths, not over contents.
Can remote access be shared?
No, for the same reason as a shared badge: revocation becomes impossible, the log becomes false, and the password circulates in messages. One account per person, an end date on supplier access.
Where we come in
The list of what at your company can be reached from the internet, each with its reason, is the only real inbound risk at your size.
- We shorten that list before discussing the purchase of any equipment.
- We give named remote access per person, never a shared account.
- We say what a firewall does not protect, which is half the subject.
At your size, inspecting encrypted traffic is expensive, slows everything and returns nothing: we will not configure it.
Read next
March’s temporary rule: rereading a firewall six months later
A rule added for a week is never removed. How to reread a rule set in two hours, and how to take one out without breaking anything.Security and surveillance: the order matters more than the product
It is the only family in the pillar bought against a fear rather than a need. And fear buys in the wrong order: what can be seen, first.What the insurer asks for: declaring, proving, being paid
The only third party that will ever examine your security does it once, after the loss. What it will ask for, and what has to exist beforehand.
Let us talk about your project
A free audit, no commitment: we look at your online presence and tell you what is holding it back.