Firewalls 101: Your Business Network's First Line of Defense
Why October 2022 Has Philippine Businesses Thinking About Network Security
The scam texts that greet you by your full name are still landing. The government has answered with the SIM Registration Act signed earlier this month — President Marcos' first law, signed October 10 — and October is Cybersecurity Awareness Month around the world. All of that attention points at the phone in your pocket. Meanwhile the network in your office carries your POS terminal, your payroll PC, and every customer record you keep — and a business firewall in the Philippines is where protecting it starts.
Worth being precise: this is an international campaign, not a Philippine proclamation. The US Cybersecurity and Infrastructure Security Agency (CISA) and the National Cybersecurity Alliance run it, and this year the theme is "See Yourself in Cyber" — security as the daily choices of ordinary people, not just equipment.
The scale here is not theoretical. Globe Telecom reported blocking roughly 784 million spam and scam text messages from January to the end of July this year, deactivating 14,058 scam-linked SIMs and blacklisting 8,973 more. One telco, seven months. Whoever is on the other end is running an operation at industrial scale — and they do not only come by SMS.
SIM registration targets fraud aimed at individual phones. It does nothing about the traffic hitting your office internet connection every minute: automated scans hunting for an open door, malware riding in on someone's browsing, ransomware probing for a forgotten remote-access login. That is a network problem, and its first line of defense is a firewall — which is where our cybersecurity services for Philippine SMEs start. Below: what a firewall actually does, why the free modem from PLDT or Globe is not one, and how to choose between an open-source build and a commercial appliance.
What Is a Firewall? A Plain-English Explainer for Business Owners
Think of a firewall as the security guard at your building lobby. Every visitor is checked against a list of rules; anyone with no business inside is turned away at the door.
The visitors are data packets — small chunks of information moving in and out of your network. Inbound traffic arrives from the internet; outbound traffic is what your devices send out. Both move through ports: numbered doorways on a device, each reserved for a service like web browsing or email.
Firewalls differ mainly in how closely they look at those visitors.
- Packet filtering — the most basic. It checks a packet's source, destination, and port, then allows or blocks it. Fast, but with no memory of what came before.
- Stateful inspection — it remembers conversations. If your accountant's PC requested a web page, the reply is let in; an uninvited packet pretending to be that reply is not.
- Application-layer, UTM, or "next-generation" firewalls — these look inside the traffic itself. UTM means unified threat management: one device that scans for malware, filters websites, and blocks intrusion attempts on top of rule-checking.
Hardware versus software, briefly. The Windows Defender Firewall on each PC is the guard inside each room; a perimeter firewall is the guard at the building entrance. A business needs both. Guarding that entrance is network perimeter security — the layer most Philippine SMEs do not have.
Isn't My PLDT or Globe Router Enough? Router NAT vs a Real Business Firewall
Fair question, and the first one owners ask us. The free ISP modem does perform one firewall-like trick: NAT, or network address translation, which lets all your devices share a single public internet address. Outsiders therefore cannot dial your office devices directly.
But that is a side effect, not a managed defense. The stock modem inspects nothing for threats, keeps almost no usable logs, offers rules you cannot meaningfully control, and runs firmware your ISP updates on its own schedule, if at all.
A dedicated business firewall adds the things you would actually miss on a bad day:
- Content and web filtering — blocks known malware and phishing domains before a browser reaches them, and keeps time-wasting sites off the work network.
- Intrusion detection and prevention (IDS/IPS) — watches for attack patterns and drops them, using proven engines like Snort or Suricata.
- VPN termination — an encrypted tunnel so hybrid staff reach office files without exposing them to the open internet, as in setting up a secure VPN for your hybrid team.
- Guest Wi-Fi and VLANs — separate zones for office, visitors, and payment devices, so trouble in one stays there.
- Usable logs — a record of what connected to what, so after an incident you can answer questions instead of guessing.
Here is the setup we find on most first visits. The POS terminal, the payroll PC, the CCTV recorder, and the guest Wi-Fi your customers log into all sit on one flat network behind the stock modem. Every device can reach every other. One compromised phone on that guest Wi-Fi — someone who tapped a scam link at lunch — has a path to the machine holding your books. With ber-months volume ramping up, that flat network carries more of your money than at any other time of year.
Fixing it is a design job before it is a hardware purchase: which devices belong in which zone, what each zone may reach, and where the firewall sits. That planning is the heart of our network consulting work, and it is what makes the firewall you buy worth its price.
pfSense for Small Business vs Fortinet-Class Appliances: Which Fits Your Budget?
Once an owner accepts that the modem is not enough, the next question is what to buy. We deploy two paths for clients; they suit different budgets and staffing realities.
The Open-Source Route: pfSense
pfSense is a free, open-source firewall operating system maintained by Netgate. It installs on a modest dedicated box — commonly a small-form-factor PC with two network ports, sometimes a repurposed one — and turns it into a full firewall: stateful rules, web filtering, intrusion prevention, and OpenVPN or IPsec VPN built in, with no license fee.
The honest trade-off is that pfSense rewards someone who knows what they are doing. Its rules are powerful because they are granular, and granular rules can be quietly misconfigured. Updates and backups are yours to schedule. The savings are in the license, not the labor.
That is precisely the pfSense small business fit: capable protection on a hardware budget, with an IT partner behind the configuration. For a growing SME, money that would go to a recurring subscription often buys more as retained engineering time.
The Commercial Route: Fortinet-Class Appliances
The other path is a purpose-built appliance, the FortiGate class from Fortinet being the one Philippine businesses meet most often. You buy the hardware, then pay a yearly security subscription that keeps its threat signatures and web-filtering categories current.
What you are really buying is somebody else keeping the threat intelligence fresh, plus vendor support with a number to call. It earns its price when you have no in-house IT, when several branches need central management, or when clients and auditors expect a named vendor on your network diagram.
As a rough fit-finder:
- Solo shop or small office, everything on-site: a properly configured pfSense build with segmented Wi-Fi is usually plenty.
- Growing office with hybrid staff and a POS: pfSense under a managed support arrangement, or an entry-level appliance if nobody in-house wants to own it.
- Multiple branches, or clients who ask what protects their data: a commercial appliance, centrally managed.
We deploy and manage both. The right answer depends more on who will maintain the thing than on the brand printed on it.
A Firewall Is Not "Set and Forget": Rules, Updates, and Layered Defense
Buying the box is the easy part. Three habits make any firewall actually work.
- Default-deny rules. Block everything, then open only what the business genuinely needs. The classic hole we still find is an exposed remote-desktop port left over from the 2020 work-from-home scramble, forgotten the moment staff returned on-site.
- Scheduled updates. Firmware and signature updates belong on a calendar, with a maintenance window and a backup taken first.
- A periodic rules review. Staff leave, apps get retired, suppliers change. Rules outlive their reasons, and a stale rule is a door nobody is watching.
Then the honest limit: a perimeter firewall cannot stop an employee from tapping a smishing link on their own phone over lunch — we explained how those messages got so personal in why scam texts know your name. People are a layer of the defense too, which is exactly what "See Yourself in Cyber" is getting at. Train them, and make it safe to report a mistake early rather than hide it.
Regulators are moving as well. In September the National Privacy Commission opened a probe into telcos, a bank, and payment platforms over the smishing wave, and an inter-agency body — with the NTC, the DICT, and others — was formed to go after the scammers. Real progress. It also runs on government time, while your network needs protection on business time.
Getting Firewall Protection Right Before the Holiday Rush
The fourth quarter is the most expensive possible moment for a breach or a day of downtime. Holiday orders are landing, 13th-month pay has to be computed and released, and by late December most offices run on a skeleton crew. Scammers know the calendar as well as you do.
A firewall engagement with us runs in four steps:
- Network assessment. We map what is exposed today — every device on the network, every service reachable from the internet, every rule your modem is or is not applying.
- Recommendation. A pfSense build or a commercial appliance, sized to your office and staff count, with the cost model laid out plainly — maintenance included.
- Deployment. The firewall goes in at the perimeter, the network is segmented into office, guest, and payment zones, VPN access is set up, and default-deny rules are documented.
- Monitoring and support. Updates applied, logs reviewed, rules revisited as the business changes.
Cybersecurity Awareness Month is better closed with action than awareness alone. Book a call with us for a free network security assessment: we will map what sits exposed behind your current modem, recommend a right-sized business firewall — open-source or commercial — and get it in place before the holiday rush.