Scoping and design
- The existing policy mapped before anything changes
- Rules designed around what is required today, not what accumulated
- Segmentation and environment separation designed in
- A platform recommendation from three — including staying put
Official partner of all three vendors
ILS Networks specifies, deploys, replaces and manages enterprise firewalls — Fortinet, Sophos and Palo Alto Networks. We are an official partner of all three, so the recommendation comes from your environment rather than from whichever brand is convenient for us to sell.
Overview
The problem is almost never the box. The problem is that the policy running on it was designed six years ago, two hundred rules have been piled on since — each one added under time pressure — and nobody in the organization can now say what half of them do or what breaks if they are removed. In that state the firewall still blocks things. It just no longer protects what needs protecting today.
So we do not start from a hardware specification. We start by mapping: who actually talks to whom, which rules are still relevant, where remote access was opened once and left open, and which environments share a space that should never have shared one. What to buy falls out of that — and sometimes the conclusion is that the existing hardware is fine and the whole problem is the policy.
And we are an official partner of all three leading vendors, not one. That sounds like a technical detail and it is not: it is what lets us recommend the platform that fits you, up to and including telling you that the equipment you already own is enough.
What the service covers
Proof
Ariston Group
A Sophos-based security estate as the central protection layer, with ten branches connected under one centrally managed security policy — so each site has its own control rather than being wired straight into the centre.
Galmarine
A Palo Alto firewall built as part of managing the organization’s entire network and systems estate, alongside the mail migration to Microsoft 365 and the enterprise storage migration.
The projects shown here are based on work delivered by the ILS team in customer environments.
FAQ
There is no single answer, and anyone who gives you one without asking questions is selling you what is convenient for them to sell. We are official partners of Fortinet, Sophos and Palo Alto Networks — so we have no interest in pushing a particular brand. The choice comes from four things: how many sites there are and how they connect, who will operate the system day to day, what is already installed and what policy runs on it, and which regulatory or customer requirements the organization has to satisfy.
Three real reasons: the hardware has reached end of support and no longer receives security updates; the organization has grown past what the appliance can carry in throughput or sessions; or the policy has accumulated over years until nobody can say what a given rule is for. The third is the most common, and it is the only one a new box alone does not fix — the policy has to be mapped and rebuilt around what is actually required today.
The work is staged, not done in one night. First the existing policy is mapped and translated into rules somebody can explain; then the new firewall is built alongside the old one; then traffic groups move across one at a time, each with a defined way back. The real outage shrinks to the cutover itself. We set the schedule with the organization after the scoping, not before it.
A firewall at the edge blocks what tries to come in. Segmentation decides what can move once something is already inside. Most serious incidents do not start by breaking through the wall — they start with one infected machine, and what decides whether that stays one incident or becomes an organization-wide one is whether the servers, the production systems and the user workstations share a space or are separated. It is the part most organizations skip, and it is usually the cheaper of the two.
Each site gets its own control and a uniform policy managed centrally, instead of being wired straight in. A fault or an incident at one branch then does not automatically become an incident for the whole organization. At Ariston we built exactly that: ten branches under one centrally managed security policy on Sophos.
Both, and it is decided up front. At some organizations the internal team operates it and we advise and step in for larger changes; at others the whole of the running is ours — version updates as controlled changes, documented policy changes, alert monitoring, and hardware faults handled with the vendor as a formal partner. Support runs alongside the rest of the infrastructure.
A classic firewall decides by address and port: who may talk to whom, on which channel. A next-generation firewall also looks at what is travelling in that channel — which application it actually is, which user is running it, and what is inside the encrypted traffic. In practice all three platforms we work with are NGFWs; the useful question is not whether, but how many of those capabilities are genuinely switched on in your environment — plenty of organizations pay for a licence that runs on defaults.
No, and this is the most common mistake. A firewall stops what arrives over the network; most incidents today arrive through a person — a file that got opened, a phishing message that worked, a password that leaked — and start from the inside. The layer that answers that is endpoint protection, and the layer that decides how much damage is done is backup. We design all three together, rather than as three products bought in three different years.
Also written: Fortinet · פורטינט · פורטיגייט · FortiGate · FortiOS
Next step
A short call with the team: what is installed today, how many rules are genuinely in use, and what you would want done differently — no commitment.
Thanks for contacting ILS Networks. We will come back to you shortly. If it is urgent, you can also call us directly.
+972-54-454-6020