Work

Owned · PLATFORM STRATEGY

Fleet-Wide Firewall Consolidation

A fleet of one-off firewalls costs you twice. Every incident starts by learning that site's particular setup, and every renewal is its own negotiation.

One platform and one policy template across 20+ environments

  • UniFi
  • Sophos
  • Site-to-site VPN
  • VLAN segmentation
  • Firewall policy design

Context

Firewalls had accumulated per site rather than been chosen. Different vendors, different licensing cycles, rule sets that used the same words to mean different things. Nobody could answer a basic question like "is this rule present everywhere" without opening every console.

What I owned

The platform decision and its consequences. The technical migration was the straightforward half. The harder part was choosing what an entire managed estate would standardize on, and being the person accountable when that choice has to survive the next hardware cycle.

Evaluation

I ran a structured comparison rather than a feature checklist, because feature checklists reward whoever writes the longest datasheet.

  • Capability against what the sites actually needed, not against the top of the product line.
  • Licensing model and its total cost across a full refresh cycle, not year one.
  • Support path and how quickly a failed unit becomes a working unit.
  • Operational cost of running many instances of it, which is where the real money goes in a managed estate.

Migration

Rule sets were rebuilt against a common template rather than translated one to one. Translation preserves every historical accident. Rebuilding forces a decision about whether each rule is still needed, and produces something you can compare across sites afterwards.

Cutovers ran off-hours with a tested rollback for each one. No site lost business hours to the program.

Result

  • Four clients migrated off the previous platform, plus a hardware refresh that retired units past end of support.
  • A single policy shape across 20+ environments, so a change can be reasoned about once and applied everywhere.
  • Lower recurring licensing spend with the same security posture and a shorter support path.

Trade-off

Standardizing on one vendor concentrates risk. If that platform has a bad year, every site has a bad year. I took that trade knowingly: the operational cost of a fragmented estate was certain and immediate, while vendor risk is real but manageable through hardware lifecycle planning.