Skip to content

Home Expertise / Network security

NET / NET-01

Next-generation firewall deployment and migration — Palo Alto Networks

Install or replace a firewall that controls network traffic and enforces security policies suited to applications and users. The project covers architecture, rule migration and operational readiness.

WHEN IT HELPS

A focused response
to a defined need.

CIO or network manager facing ageing equipment, unreadable rules, a carrier change, a new site or insufficient traffic visibility.

AT A GLANCE

Family
Network security

Engagement
Implementation

Reference
NET-01

SCOPE & OUTCOMES

What the engagement covers.

Scope

  • Sizing with enabled features
  • zones and routing
  • rule cleanup
  • security profiles
  • administrative access
  • logging
  • migration and rollback
  • high availability when included

Deliverables

  • Architecture document
  • traffic matrix
  • configuration backups
  • cutover plan
  • application tests
  • operations guide
  • subscription and dependency inventory

Acceptance evidence

Approved traffic works; prohibited traffic is blocked; events are collected; configuration recovery is tested; failover is verified when contracted.

DELIVERY

How the work is structured.

Approach

Map traffic; design and size; pilot; migrate gradually with rollback; test and document operations.

Prerequisites & responsibilities

Customer: networking, applications, carriers, change windows and business acceptance. Provider: design, migration and tests. Third-party access and TLS inspection require suitable approvals.

Scope factors

Sites, actual inspected throughput, traffic, rules, remote users, availability and integrations. Hardware, security subscriptions and recurring operations are separate.

Questions to clarify

Which throughput and applications must be preserved? What outages are acceptable? Which features and licenses are genuinely needed?

IMPORTANT BOUNDARIES

Throughput without inspection is insufficient for sizing. TLS decryption, high availability and advanced protection need separate technical, legal and licensing assessment.

Changes preserve essential services and recovery paths. Sizing, licensing and acceptance tests reflect the features that will actually be enabled.

IN PRACTICE

Illustrative situations.

These examples describe possible engagements and target outcomes. They are not customer references or achieved results.

Scenario 01

A multisite company replaces inconsistent firewalls. Project: map business traffic, remove unnecessary rules and migrate site by site. Target outcome: consistent policy and documented operations without automatically reproducing legacy exposure.

Scenario 02

A hosting provider opens a new application zone. Project: design separate zones, test protection services and connect logs to the SOC. Target outcome: controlled exposure; insufficient pilot throughput triggers resizing before production.

Technology and reference context

Examples: Palo Alto Networks hardware or virtual firewalls and compatible security profiles; confirm exact features and subscriptions.

The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.

CONNECTED SERVICES

Build the next step.

These services can complement the engagement. They are not automatically included.

START A CONVERSATION

Make the scope clear.

We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.