SWISS POST GROUP · SOVEREIGN BY DESIGN
AI Matrix
Platform
Solutions
Switch to OS
Resources
Partner
Company
Secure Access · SSE · Live

Firewall

Move to a firewall service experience for SD-WAN, OT and LAN. Follow-the-sun management and monitoring by Level-3 engineers, to block external threats and prevent lateral movement.

Overview

Firewall, operated for you.

The Open Systems Firewall Experience provides 24/7 follow-the-sun management and monitoring of firewalls by Level-3 engineers, to protect against external threats, prevent lateral movement and secure modern OT environments.

Open Systems managed firewall protecting connections across the network

Firewalls that address today's critical challenges

Evolving threats

IT and security teams struggle to manage their infrastructure and defend against threats and intrusions.

Escalating costs

Ongoing CapEx, OpEx and staff costs are unpredictable and expensive.

Talent shortage

Finding, training and retaining experienced security professionals is a challenge worldwide.

Tailored solutions

Three components, combined to fit.

Use cases

From branch to critical infrastructure.

Branch, campus and data center

High-performance, cost-effective firewalls from the data center to branch offices and campuses.

Public cloud

Extend firewall protection close to your applications for the best performance, and secure cloud-to-cloud workloads.

Operational technology

Improve your zero trust posture in critical infrastructure with a specialized OT firewall.

Secure access experience

Experts from onboarding to operations.

Comprehensive, unified, easy to use

The complete SASE portfolio at your fingertips, easy to configure and manage at a predictable cost.

Designated teams

From SASE design to project management and service delivery, a dedicated team is at your disposal.

24/7 follow-the-sun NOC

Continuous monitoring and remediation, with around-the-clock direct access to Level-3 engineers.

IT leaders rely on Open Systems Managed SASE for secure connectivity. Gartner Peer Insights reviews reflect a 98% customer retention rate.

One platform

Part of the SSE layer.

Firewall works alongside ZTNA, Secure Web Gateway, CASB and Email Security in one managed platform, on 35 years of operational baseline.

FAQ

Questions about the firewall.

If you operate the firewall, do we still own the rules?

Yes. The policy is yours and stays visible to you; what moves to us is the work of running it, 24/7 follow-the-sun monitoring, changes and remediation by Level-3 engineers. The reason to hand that over is rarely the technology. It is that finding, training and keeping firewall engineers is hard everywhere, and a rulebase nobody has time to tend is a security problem of its own.

What is the difference between the SD-WAN, LAN and OT firewalls?

Where they sit and what they are for. The SD-WAN firewall faces outward, blocking external threats with a curated block list and built-in intrusion detection. The LAN firewall works inside the network, splitting it into security zones so an intruder cannot move sideways. The OT firewall is a dedicated appliance for industrial networks that understands their protocols and their uptime constraints. Most customers combine two or three.

Do we need an appliance at every location?

Not everywhere and not always the same one. Branch, campus and data centre are covered by the managed firewall, the public cloud is covered by placing enforcement close to your applications so cloud-to-cloud traffic is protected too, and OT gets its own dedicated appliance. The sizing comes out of the design work, not out of a catalogue.

How does this actually stop lateral movement?

By making the inside of the network not one flat space. Multiple security zones mean a compromised machine in one zone cannot simply reach the next, and intrusion detection watches the traffic that does cross. Perimeter-only firewalling is what turns a single foothold into an estate-wide incident.

What happens to the rulebase we already have?

It gets reviewed and migrated rather than reinvented. Most inherited rulebases contain rules nobody dares to remove, so part of the onboarding is establishing what is still needed. A designated team handles that, from SASE design through project management to service delivery.

Who changes a rule at two in the morning, and how fast?

A Level-3 engineer in the follow-the-sun NOC, with no L1 or L2 queue in between. That is the point of the service model: the person who picks up is the person who can make the change and answer for it.

Does this make cost more predictable?

That is usually why finance signs it. Instead of ongoing CapEx for hardware refreshes, OpEx for maintenance and staff costs that scale with headcount, it is a predictable per-service fee. What it does not do is remove the cost of your own decisions about what to allow.
Resources

Go deeper.

Leave complexity behind.

See how Open Systems runs Firewall and the full SASE Experience for your organization.

Contact us
Already a customerEverything you use today keeps running.