Short answer
An on-site firewall suits organisations with data sovereignty or latency requirements, local internet breakout, or high WAN throughput, because the appliance sits on your premises. A hosted firewall suits organisations that want managed protection without owning or maintaining an appliance, prefer a monthly operating expense, or are rolling out many sites where a centrally hosted service is simpler to operate.
In detail
Other factors FirstNet weighs:
- Design flexibility: a dedicated on-site firewall offers the most customer-specific design and dedicated HA
- Cost model: a hosted firewall avoids buying an appliance, and Fortinet Hosted VDOM can act as the firewall layer for FirstNet Private Cloud workloads
- Features: Sophos offers the same feature set on site or hosted, set by Standard or Xstream Protection; on Fortinet, Hosted VDOM Lite suits simpler needs while Enterprise adds advanced security
- Responsibility: with a hosted firewall, on-site cabling, ISP handoffs and local switching stay with you unless scoped
FirstNet manages both options, and the right choice is usually confirmed in a short discovery session covering sites, users, links and VPN needs.
Source: FirstNet Hosted Firewall & Network Security service page →
Didn’t answer your question?
