keep style the same 202605041000 scaled

Ask FirstNet about Security

Hosted Firewall & Network Security

Multi‑tenant, enterprise‑grade firewalling for IaaS and connected sites without hardware overhead.

The Challenge

Closing the security gap

As networks expand and workloads move to cloud, security must keep pace. Traditional appliance models can be slow to scale and costly to manage across many sites or tenants.

You need strong segmentation, policy consistency, and 24/7 monitoring, delivered as a managed service.

Quick answers

What is a VDOM?

A Virtual Domain is an isolated firewall instance running on shared hardware, giving you dedicated policies and logs without a physical device.

Full answer in the Knowledge Hub

Can you integrate with our SIEM?

Yes. We export logs and alerts to your SIEM or provide reporting dashboards.

How are changed handled?

Changes follow approved workflows with testing and rollbacks to maintain stability.

What is the difference between Fortinet Hosted VDOM and Sophos Shared Firewall?

Hosted VDOM gives you an isolated virtual firewall instance on FirstNet's shared FortiGate platform. Sophos Shared Firewall gives each customer a dedicated Sophos Firewall Virtual machine on FirstNet's hypervisor. Both are hosted and managed by FirstNet; the right choice depends on your preferred platform and feature needs.

Full answer in the Knowledge Hub

Our Expertise

Hosted firewall services

We provide hosted firewall services using FortiNet Virtual Domains (VDOMs) to deliver dedicated, isolated security contexts per customer or business unit. Policies, logging, and updates are centrally managed by our security team.

This model scales quickly, reduces hardware footprint, and aligns with both private cloud and connectivity services for end‑to‑end protection.

  • Dedicated Security Contexts: per‑tenant VDOMs for clean separation.
  • Scalable Controls: add capacity or features without on‑site hardware swaps.
  • Managed Service: patching, ruleset hygiene, and monitored alerts
  • Integrated Connectivity: consistent policies across sites and cloud.
Glass padlock on a glowing circuit board, representing a hosted firewall

How We Deliver

Blend robust tech with disciplined operations

At FirstNet, our service blends robust technology with disciplined operations and transparent reporting.

Design & Policy

Define zones, segmentation and least-privilege access.

Build & Onboard

Migrate rules safely with validation and rollback plans.

Operate

Monitoring, tuning, and regular posture reviews.

Report

Monthly summaries, change records, and improvement actions.

Explore the details

Case studies: Financial services and public sectorConsolidated branch firewalls into hosted VDOMs, improving control and reducing costs. · Standardised…
Presenter explaining financial dashboards to colleagues

Financial Services

Consolidated branch firewalls into hosted VDOMs, improving control and reducing costs.

Three colleagues talking in a bright office

Public Sector

Standardised security policies across multiple agencies with centralised visibility.

Two platforms, on site or hostedFirewall as a Service is available on Fortinet or Sophos. First choose where the firewall lives, at your…

Delivery options

Two platforms, on site or hosted

Firewall as a Service is available on Fortinet or Sophos. First choose where the firewall lives, at your site or hosted by FirstNet, then choose the level of protection. FirstNet configures, monitors, updates and supports the firewall in every option.

Fortinet On Prem FWaaS

A dedicated FortiGate at your site, managed by FirstNet. Best when you want local control, more customisation, dedicated HA or customer-specific integration.

Fortinet Hosted VDOM Lite

A hosted firewall on FirstNet's FortiGate platform for firewalling, NAT, routing, segmentation and site-to-site VPN. Suits smaller or simpler environments.

Fortinet Hosted VDOM Enterprise

Everything in Lite plus advanced security and networking: IPS, antivirus, web filtering, application control, SSL inspection and SD-WAN where required and sized correctly.

Sophos On-Premise FWaaS

A dedicated Sophos Firewall XGS appliance at your site, managed through Sophos Central. Suits data sovereignty, latency, local breakout or high WAN throughput needs.

Sophos Shared Firewall

A dedicated Sophos Firewall Virtual instance for each customer on FirstNet's platform. Every customer gets their own firewall VM, so there is no shared firewall instance.

Sophos Standard or Xstream

Standard covers firewall, IPS, web protection, VPN, TLS inspection and X-Ops threat intelligence. Xstream adds sandboxing, SD‑WAN orchestration, DNS Protection, NDR Essentials and 30-day cloud reporting.

Central control and South African log analyticsFor Fortinet estates, FirstNet adds a managed management plane and a managed log analytics layer…

Fortinet management

Central control and South African log analytics

For Fortinet estates, FirstNet adds a managed management plane and a managed log analytics layer. FortiManager plans and pushes change, FortiGate enforces it, and FortiAnalyzer captures the evidence, giving you a complete change-and-evidence loop.

  • FortiAnalyzer storage bundles start at 50 GB and step up in 50 GB
  • Rule of thumb: 100 GB holds about 90 days at 1 GB per day
  • FirstNet alerts you before ingest reaches your bundle ceiling
  • Quarterly firmware programme keeps the managed estate aligned
  • Monthly reports on policy revisions, firmware drift and licence use

Managed FortiManager

One console for FortiGate, FortiSwitch, FortiAP, FortiExtender and FortiSandbox. Policy packages are validated with an install preview before every push, with one-click rollback at device and ADOM level.

Administrative Domains (ADOMs)

Each customer, business unit or environment gets its own ADOM with separate policies, objects and admin scope. FirstNet designs the ADOM model before any device is enrolled.

Zero-Touch Provisioning

Ship a FortiGate to a new site and plug it in. It calls home, FortiManager hands it its configuration and the site goes live.

FortiAnalyzer as a Service

A dedicated FortiAnalyzer-VM hosted in South Africa and operated by FirstNet, including patching, upgrades, backups and capacity monitoring. Billed in rands as a monthly storage bundle.

What we need from youFirewalls are sized on real inspected traffic, not line speed. Enabled security features and SSL…

Onboarding

What we need from you

Firewalls are sized on real inspected traffic, not line speed. Enabled security features and SSL inspection have the biggest effect on the right model, so we gather these inputs during discovery before recommending a track.

  • Users, devices, sites and expected growth over 12 to 36 months
  • Peak inspected throughput and how much traffic needs SSL inspection
  • ISP handoff, circuit, bandwidth, public IP and failover details
  • Subnets, VLANs, routing and NAT requirements
  • VPN peers, tunnel purposes and remote-user numbers
  • Firewall policy needs: sources, destinations, ports and published services
  • Authorised technical contacts, approvers and maintenance windows
  • Support level required: 8x5 or 24x7

We’ve got your security covered. Choose us as your long-term partner.

FAQs

Questions,
answered.

Straight answers from the FirstNet team.

More in the Knowledge Hub →

Why Choose FirstNet

Superior scalability and cost control

Can we see our firewall configuration and logs?

Yes. Read-only visibility is available on request through Sophos Central or a read-only FortiManager ADOM profile. Write access to production is an exception that needs explicit approval, because it changes the managed-service operating model.

Full answer in the Knowledge Hub

Is FortiAnalyzer as a Service the same as FortiAnalyzer Cloud?

No. FortiAnalyzer Cloud is Fortinet's own service, typically hosted in US or EU regions and billed in dollars. FirstNet's service is hosted in South Africa, billed in rands and operated by FirstNet, so log data stays in South Africa during normal operation.

Full answer in the Knowledge Hub

Does FortiAnalyzer replace our SIEM?

No. It is the Fortinet-native analytics and reporting layer, sitting closer to your FortiGates and providing out-of-the-box compliance reports. If you already use Splunk or Sentinel, keep it; log forwarding to your SIEM can be scoped separately.

Full answer in the Knowledge Hub

What happens if FortiManager goes down?

Production FortiManager runs as an HA pair with daily configuration backups and a documented recovery runbook. Your FortiGates keep enforcing policy locally during a management-plane outage, so traffic is not dropped.

Full answer in the Knowledge Hub

What happens to our data when the contract ends?

You retain ownership of your data and configurations. FirstNet supports an agreed handover and deprovisioning process, and FortiAnalyzer logs are exportable on exit. Migration work outside the standard service is scoped separately.

Full answer in the Knowledge Hub

What is firewall as a service (FWaaS)?

Firewall as a service is a managed firewall service: instead of buying and running the firewall platform yourself, FirstNet provides, configures and supports it for you. FirstNet handles firewall policy, updates, monitoring, change management and incident response within the agreed scope. You can choose a dedicated firewall at your own site or a firewall hosted on FirstNet's platform. FirstNet offers FWaaS on both Fortinet and Sophos technology, and support is available in 8x5 or 24x7 options.

Full answer in the Knowledge Hub

Should our firewall be on site or hosted by FirstNet?

An on-site firewall suits organisations with data sovereignty or latency requirements, local internet breakout, or high WAN throughput, because the appliance sits on your premises. A hosted firewall suits organisations that want managed protection without owning or maintaining an appliance, prefer a monthly operating expense, or are rolling out many sites where a centrally hosted service is simpler to operate. FirstNet manages both options, and the right choice is usually confirmed in a short discovery session covering sites, users, links and VPN needs.

Full answer in the Knowledge Hub

What is the difference between Fortinet Hosted VDOM Lite and Enterprise?

Hosted VDOM Lite is for simpler needs: basic firewalling, NAT, routing and VPN. Hosted VDOM Enterprise adds advanced security and networking, including unified threat management features such as intrusion prevention, antivirus, web filtering and application control, plus SSL inspection and SD-WAN where required. Both are hosted firewall services run by FirstNet on its FortiGate platform. If you need a dedicated firewall with more customer-specific design flexibility, FirstNet's On Prem FWaaS track places a FortiGate at your site instead.

Full answer in the Knowledge Hub

What is the difference between Sophos Standard Protection and Xstream Protection?

Standard Protection covers core firewall needs: firewalling, NAT, routing, site-to-site and remote-access VPN, intrusion prevention, web protection, application control, TLS inspection and Sophos X-Ops threat intelligence. Xstream Protection adds zero-day protection through sandboxing and machine-learning file analysis, SD-WAN orchestration, DNS Protection, NDR Essentials and advanced reporting with 30-day cloud log retention. Both bundles are available whether your Sophos firewall sits on site or is hosted by FirstNet, so the choice depends on your security needs rather than where the firewall lives.

Full answer in the Knowledge Hub

How do you size a firewall correctly?

A firewall should be sized on your real peak inspected traffic, not on your internet line speed. Sizing considers total and concurrent users, the number of devices (including BYOD, IoT and servers), peak throughput, which security features will be enabled, and how much traffic needs SSL/TLS inspection, which is often the biggest sizing factor. VPN tunnels and remote users, concurrent sessions, interface requirements, high availability and expected growth over the next 12 to 36 months also affect which model is right.

Full answer in the Knowledge Hub

What is Sophos Synchronized Security?

Synchronized Security lets a Sophos firewall and Sophos endpoint protection (Intercept X) share information automatically. Through Security Heartbeat, each device reports a real-time health status, and the firewall can automatically isolate a compromised device from the network. It is included when you run a Sophos firewall alongside another Sophos product. You can keep a different endpoint vendor and the Sophos firewall will still protect you, but this automatic firewall-to-endpoint response only works with Sophos endpoints.

Full answer in the Knowledge Hub

What does FirstNet manage, and what remains our responsibility, with a managed firewall?

FirstNet manages the firewall itself: configuration, policy, firmware and signature updates, monitoring, approved changes and incident response within the contracted scope. You remain responsible for your internal LAN, endpoints, cabling, ISP handoffs and applications unless these are separately agreed, and for providing accurate inputs such as rules, VPN peer details and certificates. Onsite hands-and-feet support is not part of the standard service. Full network redesigns, security audits and penetration testing are scoped separately.

Full answer in the Knowledge Hub

How long are Sophos firewall logs kept?

With Standard Protection, logs are kept on the firewall for seven days with basic reporting in Sophos Central. Xstream Protection adds Central Firewall Reporting Advanced, with 30-day cloud log retention and multi-firewall reporting. If you need longer retention, logs can be retained through Sophos MDR's data lake or forwarded to a SIEM you manage via syslog. The retention approach and any integration are confirmed during the design phase.

Full answer in the Knowledge Hub

What is FortiAnalyzer as a Service (FAZaaS)?

FAZaaS is FirstNet's managed FortiAnalyzer service for centralised log analytics, compliance reporting, threat correlation and incident investigation across your Fortinet devices. FirstNet runs a dedicated FortiAnalyzer-VM instance for you on FirstNet-operated infrastructure in South Africa and handles patching, upgrades, backups, capacity monitoring and routine platform operations. You pay a monthly service in rand based on a storage bundle, so there is no hardware to buy, no virtual machine to run and no Fortinet licence to manage yourself.

Full answer in the Knowledge Hub

How much FortiAnalyzer storage do we need?

FAZaaS is sold in storage bundles starting at 50 GB and increasing in 50 GB steps. As a rule of thumb, 100 GB holds about 90 days of logs at 1 GB per day, measured before compression. A small office with one to three FortiGates and little SSL inspection typically fits 50 GB, while larger estates with active SSL inspection or retention beyond 90 days need more. FirstNet sizes the bundle from your device count, daily log volume and retention needs, and recommends sizing up if your estate is growing.

Full answer in the Knowledge Hub

What happens if our logs outgrow our FortiAnalyzer storage bundle?

Your storage bundle is a hard ceiling, but FirstNet monitors ingestion trends and alerts you before you reach it so the bundle can be stepped up. There are no silent overage charges. It is important to act on these alerts, because logs above the ceiling are not stored. Log volume can also change quickly, for example if full SSL deep inspection is switched on mid-contract, so FirstNet recommends re-baselining log volume after about six months.

Full answer in the Knowledge Hub

Do FortiAnalyzer logs stay in South Africa, and who is responsible under POPIA?

With FAZaaS, log data is held on FirstNet-operated infrastructure in South Africa and, under normal service operation, remains within that South African hosting footprint. FirstNet carries the operational responsibility for the hosted platform, but your organisation remains the responsible party under POPIA, so your obligations to data subjects and your internal governance stay unchanged. This positioning applies to FAZaaS specifically. If you buy FortiAnalyzer Cloud directly from Fortinet, it is typically hosted in US or EU regions.

Full answer in the Knowledge Hub

Request a security architecture session to map segmentation, policies, and migration into hosted firewalls.

Your place in the stack

Security is layer 3 of 5.

Enriched by Sovereign AI Keep AI POPIA-aligned: prompts, documents and data are processed on South African infrastructure instead of foreign APIs. Explore the AI Factory →

  1. Sovereign AI
  2. Voice
  3. Security
  4. Cloud
  5. Connectivity
Call