
Ask FirstNet about Security
Hosted Firewall & Network Security
Multi‑tenant, enterprise‑grade firewalling for IaaS and connected sites without hardware overhead.
The Challenge
Closing the security gap
As networks expand and workloads move to cloud, security must keep pace. Traditional appliance models can be slow to scale and costly to manage across many sites or tenants.
You need strong segmentation, policy consistency, and 24/7 monitoring, delivered as a managed service.
Quick answers
What is a VDOM?
A Virtual Domain is an isolated firewall instance running on shared hardware, giving you dedicated policies and logs without a physical device.
Can you integrate with our SIEM?
Yes. We export logs and alerts to your SIEM or provide reporting dashboards.
How are changed handled?
Changes follow approved workflows with testing and rollbacks to maintain stability.
What is the difference between Fortinet Hosted VDOM and Sophos Shared Firewall?
Hosted VDOM gives you an isolated virtual firewall instance on FirstNet's shared FortiGate platform. Sophos Shared Firewall gives each customer a dedicated Sophos Firewall Virtual machine on FirstNet's hypervisor. Both are hosted and managed by FirstNet; the right choice depends on your preferred platform and feature needs.
Our Expertise
Hosted firewall services
We provide hosted firewall services using FortiNet Virtual Domains (VDOMs) to deliver dedicated, isolated security contexts per customer or business unit. Policies, logging, and updates are centrally managed by our security team.
This model scales quickly, reduces hardware footprint, and aligns with both private cloud and connectivity services for end‑to‑end protection.
- Dedicated Security Contexts: per‑tenant VDOMs for clean separation.
- Scalable Controls: add capacity or features without on‑site hardware swaps.
- Managed Service: patching, ruleset hygiene, and monitored alerts
- Integrated Connectivity: consistent policies across sites and cloud.
How We Deliver
Blend robust tech with disciplined operations
At FirstNet, our service blends robust technology with disciplined operations and transparent reporting.
Design & Policy
Define zones, segmentation and least-privilege access.
Build & Onboard
Migrate rules safely with validation and rollback plans.
Operate
Monitoring, tuning, and regular posture reviews.
Report
Monthly summaries, change records, and improvement actions.
Explore the details
Case studies: Financial services and public sectorConsolidated branch firewalls into hosted VDOMs, improving control and reducing costs. · Standardised…

Financial Services
Consolidated branch firewalls into hosted VDOMs, improving control and reducing costs.

Public Sector
Standardised security policies across multiple agencies with centralised visibility.
Two platforms, on site or hostedFirewall as a Service is available on Fortinet or Sophos. First choose where the firewall lives, at your…
Delivery options
Two platforms, on site or hosted
Firewall as a Service is available on Fortinet or Sophos. First choose where the firewall lives, at your site or hosted by FirstNet, then choose the level of protection. FirstNet configures, monitors, updates and supports the firewall in every option.
Fortinet On Prem FWaaS
A dedicated FortiGate at your site, managed by FirstNet. Best when you want local control, more customisation, dedicated HA or customer-specific integration.
Fortinet Hosted VDOM Lite
A hosted firewall on FirstNet's FortiGate platform for firewalling, NAT, routing, segmentation and site-to-site VPN. Suits smaller or simpler environments.
Fortinet Hosted VDOM Enterprise
Everything in Lite plus advanced security and networking: IPS, antivirus, web filtering, application control, SSL inspection and SD-WAN where required and sized correctly.
Sophos On-Premise FWaaS
A dedicated Sophos Firewall XGS appliance at your site, managed through Sophos Central. Suits data sovereignty, latency, local breakout or high WAN throughput needs.
Sophos Shared Firewall
A dedicated Sophos Firewall Virtual instance for each customer on FirstNet's platform. Every customer gets their own firewall VM, so there is no shared firewall instance.
Sophos Standard or Xstream
Standard covers firewall, IPS, web protection, VPN, TLS inspection and X-Ops threat intelligence. Xstream adds sandboxing, SD‑WAN orchestration, DNS Protection, NDR Essentials and 30-day cloud reporting.
Central control and South African log analyticsFor Fortinet estates, FirstNet adds a managed management plane and a managed log analytics layer…
Fortinet management
Central control and South African log analytics
For Fortinet estates, FirstNet adds a managed management plane and a managed log analytics layer. FortiManager plans and pushes change, FortiGate enforces it, and FortiAnalyzer captures the evidence, giving you a complete change-and-evidence loop.
- FortiAnalyzer storage bundles start at 50 GB and step up in 50 GB
- Rule of thumb: 100 GB holds about 90 days at 1 GB per day
- FirstNet alerts you before ingest reaches your bundle ceiling
- Quarterly firmware programme keeps the managed estate aligned
- Monthly reports on policy revisions, firmware drift and licence use
Managed FortiManager
One console for FortiGate, FortiSwitch, FortiAP, FortiExtender and FortiSandbox. Policy packages are validated with an install preview before every push, with one-click rollback at device and ADOM level.
Administrative Domains (ADOMs)
Each customer, business unit or environment gets its own ADOM with separate policies, objects and admin scope. FirstNet designs the ADOM model before any device is enrolled.
Zero-Touch Provisioning
Ship a FortiGate to a new site and plug it in. It calls home, FortiManager hands it its configuration and the site goes live.
FortiAnalyzer as a Service
A dedicated FortiAnalyzer-VM hosted in South Africa and operated by FirstNet, including patching, upgrades, backups and capacity monitoring. Billed in rands as a monthly storage bundle.
What we need from youFirewalls are sized on real inspected traffic, not line speed. Enabled security features and SSL…
Onboarding
What we need from you
Firewalls are sized on real inspected traffic, not line speed. Enabled security features and SSL inspection have the biggest effect on the right model, so we gather these inputs during discovery before recommending a track.
- Users, devices, sites and expected growth over 12 to 36 months
- Peak inspected throughput and how much traffic needs SSL inspection
- ISP handoff, circuit, bandwidth, public IP and failover details
- Subnets, VLANs, routing and NAT requirements
- VPN peers, tunnel purposes and remote-user numbers
- Firewall policy needs: sources, destinations, ports and published services
- Authorised technical contacts, approvers and maintenance windows
- Support level required: 8x5 or 24x7
We’ve got your security covered. Choose us as your long-term partner.
Why Choose FirstNet
Superior scalability and cost control
Can we see our firewall configuration and logs?
Yes. Read-only visibility is available on request through Sophos Central or a read-only FortiManager ADOM profile. Write access to production is an exception that needs explicit approval, because it changes the managed-service operating model.
Is FortiAnalyzer as a Service the same as FortiAnalyzer Cloud?
No. FortiAnalyzer Cloud is Fortinet's own service, typically hosted in US or EU regions and billed in dollars. FirstNet's service is hosted in South Africa, billed in rands and operated by FirstNet, so log data stays in South Africa during normal operation.
Does FortiAnalyzer replace our SIEM?
No. It is the Fortinet-native analytics and reporting layer, sitting closer to your FortiGates and providing out-of-the-box compliance reports. If you already use Splunk or Sentinel, keep it; log forwarding to your SIEM can be scoped separately.
What happens if FortiManager goes down?
Production FortiManager runs as an HA pair with daily configuration backups and a documented recovery runbook. Your FortiGates keep enforcing policy locally during a management-plane outage, so traffic is not dropped.
What happens to our data when the contract ends?
You retain ownership of your data and configurations. FirstNet supports an agreed handover and deprovisioning process, and FortiAnalyzer logs are exportable on exit. Migration work outside the standard service is scoped separately.
What is firewall as a service (FWaaS)?
Firewall as a service is a managed firewall service: instead of buying and running the firewall platform yourself, FirstNet provides, configures and supports it for you. FirstNet handles firewall policy, updates, monitoring, change management and incident response within the agreed scope. You can choose a dedicated firewall at your own site or a firewall hosted on FirstNet's platform. FirstNet offers FWaaS on both Fortinet and Sophos technology, and support is available in 8x5 or 24x7 options.
Should our firewall be on site or hosted by FirstNet?
An on-site firewall suits organisations with data sovereignty or latency requirements, local internet breakout, or high WAN throughput, because the appliance sits on your premises. A hosted firewall suits organisations that want managed protection without owning or maintaining an appliance, prefer a monthly operating expense, or are rolling out many sites where a centrally hosted service is simpler to operate. FirstNet manages both options, and the right choice is usually confirmed in a short discovery session covering sites, users, links and VPN needs.
What is the difference between Fortinet Hosted VDOM Lite and Enterprise?
Hosted VDOM Lite is for simpler needs: basic firewalling, NAT, routing and VPN. Hosted VDOM Enterprise adds advanced security and networking, including unified threat management features such as intrusion prevention, antivirus, web filtering and application control, plus SSL inspection and SD-WAN where required. Both are hosted firewall services run by FirstNet on its FortiGate platform. If you need a dedicated firewall with more customer-specific design flexibility, FirstNet's On Prem FWaaS track places a FortiGate at your site instead.
What is the difference between Sophos Standard Protection and Xstream Protection?
Standard Protection covers core firewall needs: firewalling, NAT, routing, site-to-site and remote-access VPN, intrusion prevention, web protection, application control, TLS inspection and Sophos X-Ops threat intelligence. Xstream Protection adds zero-day protection through sandboxing and machine-learning file analysis, SD-WAN orchestration, DNS Protection, NDR Essentials and advanced reporting with 30-day cloud log retention. Both bundles are available whether your Sophos firewall sits on site or is hosted by FirstNet, so the choice depends on your security needs rather than where the firewall lives.
How do you size a firewall correctly?
A firewall should be sized on your real peak inspected traffic, not on your internet line speed. Sizing considers total and concurrent users, the number of devices (including BYOD, IoT and servers), peak throughput, which security features will be enabled, and how much traffic needs SSL/TLS inspection, which is often the biggest sizing factor. VPN tunnels and remote users, concurrent sessions, interface requirements, high availability and expected growth over the next 12 to 36 months also affect which model is right.
What is Sophos Synchronized Security?
Synchronized Security lets a Sophos firewall and Sophos endpoint protection (Intercept X) share information automatically. Through Security Heartbeat, each device reports a real-time health status, and the firewall can automatically isolate a compromised device from the network. It is included when you run a Sophos firewall alongside another Sophos product. You can keep a different endpoint vendor and the Sophos firewall will still protect you, but this automatic firewall-to-endpoint response only works with Sophos endpoints.
What does FirstNet manage, and what remains our responsibility, with a managed firewall?
FirstNet manages the firewall itself: configuration, policy, firmware and signature updates, monitoring, approved changes and incident response within the contracted scope. You remain responsible for your internal LAN, endpoints, cabling, ISP handoffs and applications unless these are separately agreed, and for providing accurate inputs such as rules, VPN peer details and certificates. Onsite hands-and-feet support is not part of the standard service. Full network redesigns, security audits and penetration testing are scoped separately.
How long are Sophos firewall logs kept?
With Standard Protection, logs are kept on the firewall for seven days with basic reporting in Sophos Central. Xstream Protection adds Central Firewall Reporting Advanced, with 30-day cloud log retention and multi-firewall reporting. If you need longer retention, logs can be retained through Sophos MDR's data lake or forwarded to a SIEM you manage via syslog. The retention approach and any integration are confirmed during the design phase.
What is FortiAnalyzer as a Service (FAZaaS)?
FAZaaS is FirstNet's managed FortiAnalyzer service for centralised log analytics, compliance reporting, threat correlation and incident investigation across your Fortinet devices. FirstNet runs a dedicated FortiAnalyzer-VM instance for you on FirstNet-operated infrastructure in South Africa and handles patching, upgrades, backups, capacity monitoring and routine platform operations. You pay a monthly service in rand based on a storage bundle, so there is no hardware to buy, no virtual machine to run and no Fortinet licence to manage yourself.
How much FortiAnalyzer storage do we need?
FAZaaS is sold in storage bundles starting at 50 GB and increasing in 50 GB steps. As a rule of thumb, 100 GB holds about 90 days of logs at 1 GB per day, measured before compression. A small office with one to three FortiGates and little SSL inspection typically fits 50 GB, while larger estates with active SSL inspection or retention beyond 90 days need more. FirstNet sizes the bundle from your device count, daily log volume and retention needs, and recommends sizing up if your estate is growing.
What happens if our logs outgrow our FortiAnalyzer storage bundle?
Your storage bundle is a hard ceiling, but FirstNet monitors ingestion trends and alerts you before you reach it so the bundle can be stepped up. There are no silent overage charges. It is important to act on these alerts, because logs above the ceiling are not stored. Log volume can also change quickly, for example if full SSL deep inspection is switched on mid-contract, so FirstNet recommends re-baselining log volume after about six months.
Do FortiAnalyzer logs stay in South Africa, and who is responsible under POPIA?
With FAZaaS, log data is held on FirstNet-operated infrastructure in South Africa and, under normal service operation, remains within that South African hosting footprint. FirstNet carries the operational responsibility for the hosted platform, but your organisation remains the responsible party under POPIA, so your obligations to data subjects and your internal governance stay unchanged. This positioning applies to FAZaaS specifically. If you buy FortiAnalyzer Cloud directly from Fortinet, it is typically hosted in US or EU regions.
Request a security architecture session to map segmentation, policies, and migration into hosted firewalls.
From the Knowledge Hub
In-depth answers about Hosted Firewall & Network Security
- How does FirstNet handle changes to our managed firewall?
- Can we move our self-hosted FortiAnalyzer to FirstNet's managed FAZaaS?
- Can FirstNet's managed firewall service send logs and alerts to our SIEM?
- How does FortiManager reduce the risk of firewall changes in FirstNet's managed service?
- When does an organisation need FortiManager, and how does FirstNet run it?
- How do FortiManager and FortiAnalyzer work together in FirstNet's Fortinet service?
Your place in the stack
Security is layer 3 of 5.
Enriched by Sovereign AI Keep AI POPIA-aligned: prompts, documents and data are processed on South African infrastructure instead of foreign APIs. Explore the AI Factory →



