South Africa

Next-Generation Firewall Management

Enterprise-grade network perimeter security — managed and monitored by ROI Technologies.

ROI Technologies designs, deploys and manages next-generation firewalls for South African businesses, supporting FortiGate (Fortinet) and Sophos firewall platforms.

Sound familiar?

Sound Familiar?

Networks tend to get attention only when they stop working. These are the states we most often find them in:

  • The Wi-Fi is fine in some parts of the building and unusable in others.
  • Nobody has a current network diagram.
  • Your firewall was configured by someone who has since left, and the rules haven't been reviewed since.
  • The network works, but nobody can say whether it's secure.
  • Everything sits on one flat network because that's how it was set up years ago.
  • When the line goes down the business stops, and there's no fallback.
What's included

What's included in our NGFW service

Everything you need from a modern ngfw partner — delivered by our engineering team.

  • FortiGate and Sophos firewall platforms supported
  • Intrusion prevention system (IPS)
  • Application control and web filtering
  • SSL/TLS deep packet inspection
  • Site-to-site and remote access VPN
  • SD-WAN capability (FortiGate)
  • 24/7 firewall monitoring and alerting
  • Firewall rule review and hardening
  • CIS benchmark firewall hardening
  • Centralised management and reporting
Why switch

How we design and run networks

A network that works on the day it is installed is a low bar. The question is whether it still works, and is still secure, three years and two staff changes later.

Designed so one failure doesn't stop the business

We look for single points of failure and remove the ones worth removing — internet failover, resilient paths, sensible hardware choices. Not every business needs full redundancy, but every business should know where its single points of failure are.

Segmented by default

Flat networks are convenient right up until something gets onto one. Segmentation, VLANs, controlled management interfaces and separated guest access limit how far a problem can travel, and are far cheaper to build in than to retrofit.

Documented so you aren't dependent on one person's memory

Network diagrams, IP addressing, VLAN allocations, firewall rules, VPN configuration and device inventory, all kept current. The most expensive networks we inherit are the ones nobody wrote down.

Managed after it's built

Firmware kept current, configuration backed up, and availability, utilisation, packet loss and latency monitored. Installation is a project; keeping it healthy is the service.

FAQ

Frequently asked questions

Do we need to replace everything?

Usually not. We assess what you have, what it can still do, and where it genuinely limits you. Equipment past support or unable to meet a security requirement should be replaced; equipment that is simply older than you'd like often has years left. We'd rather sequence upgrades around your budget than sell a refresh.

What is network segmentation, and why does it keep coming up?

Dividing the network so that not everything can reach everything else — separating guest Wi-Fi from company systems, keeping servers apart from general workstations, isolating equipment that can't be secured. It comes up constantly because it is one of the highest-value controls available, and because flat networks are still the norm in businesses that have grown organically.

Our Wi-Fi is unreliable in parts of the building. Is that fixable?

Nearly always. Poor coverage is usually a design problem rather than a hardware one — access points positioned for convenience rather than coverage, channel interference, or capacity planned for a smaller team than you now have. A survey establishes what is actually happening before anything is bought.

What happens when our internet line fails?

That depends entirely on whether it was planned for. Failover to a secondary connection can be automatic, but it needs designing, and the sensible starting point is deciding what the business can tolerate. For some businesses an hour offline is an inconvenience; for others it stops trading.

How often should firewall rules be reviewed?

More often than they are. Rules accumulate — added for a project, a supplier, a staff member — and are almost never removed. Periodic review is part of how we run firewalls, because the risk isn't usually a badly configured rule, it's the forgotten one that's still open.

Can you work with the equipment we already have?

Yes, within reason. We have platforms we know deeply and prefer to standardise on — Fortinet firewalls among them — because standardisation makes environments supportable. Where you have something different that is doing its job, we'll support it and tell you honestly if and when it becomes the constraint.

More services

Other IT services

Need NGFW?

Get a free assessment today and see how ROI Technologies can streamline your IT.

Book a Free Assessment