Our news

Firewall deployment in a company: a complete guide

Firewall deployment in a company

Protecting a company's network is not simply a matter of installing a single firewall and forgetting about it. The deployment of firewalls within a company—that is, where they are placed, how many are needed, and how they are configured—largely determines the actual level of protection the organization can achieve. In this article, we explain the key criteria for designing an effective perimeter security architecture.

What is a firewall and what is its function in a corporate network?

A firewall is a security system that controls incoming and outgoing network traffic according to a set of predefined rules. Its main function is to act as a barrier between a company's internal network and the internet, allowing only authorized communications and blocking those that may pose a risk.

However, modern firewalls go far beyond port and protocol filtering. Next-generation firewalls (NGFWs) integrate deep packet inspection, intrusion detection, application control, and content filtering, offering much more comprehensive protection against today's threats.

Types of firewalls and their impact on firewall deployment in a company

Before defining the firewall deployment in a company, it's helpful to understand the main types available. Packet-filtering firewalls analyze the headers of data packets and apply basic accept or reject rules. On the other hand, stateful inspection firewalls take into account the context of active connections, making them more effective against sophisticated attacks.

Application firewalls, or proxies, act as intermediaries between the client and the server, inspecting the content of communications at the application level. Finally, next-generation firewalls combine all these capabilities with advanced features such as real-time threat detection.

Where to place them

The location within the network architecture is critical to ensuring effective protection. In most companies, the basic setup includes a perimeter firewall located between the internet and the corporate network, which acts as the first line of defense by filtering external traffic.

However, a more robust firewall setup in a company also includes internal network segmentation using internal firewalls or DMZs. A demilitarized zone (DMZ) is an intermediate network segment where servers that need to be accessible from the internet—such as web or mail servers—are located without being directly exposed to the internal network. This way, even if a server in the DMZ is compromised, the attacker does not automatically gain access to the rest of the network.

What is the difference between implementing the standard and getting certified?

Implementing it means applying its requirements within the organization. Certification means that an independent certification body audits the system and verifies that it meets all requirements, issuing a certificate valid for three years subject to annual follow-up audits.

Therefore, a company can implement the standard without certification and still obtain the operational and management benefits it provides. Certification also adds external recognition that strengthens the trust of customers and partners.

How many firewalls does a company need?

There is no single answer. The number of firewalls needed depends on the size of the company, the complexity of its network, the type of information it manages, and its level of risk exposure. Consequently, firewall deployment in a small company can be resolved with a single, well-configured device, while a medium-sized or large organization will require a multi-layered architecture.

In general, it is recommended to consider at least the following control points: the perimeter between the Internet and the corporate network, access to sensitive areas such as database servers or production systems, and remote access connections via VPN.

Firewall deployment in a company with cloud environments

With the widespread adoption of cloud services, the deployment of firewalls in a company has evolved significantly. It is no longer enough to protect the physical perimeter of the network: it is also necessary to control traffic to and from the cloud services used by the organization.

Therefore, many companies complement their perimeter firewall with cloud security solutions that protect access to SaaS applications, control remote user connections, and apply consistent security policies regardless of where the user or data is located.

Configuration and maintenance: keys to effective protection

A well-designed firewall system in a company can be ineffective if the device is misconfigured. Therefore, initial configuration should be performed by a specialist familiar with the network architecture and the specific needs of each organization. Furthermore, regular maintenance is essential: rules should be reviewed regularly, firmware should be updated, and activity logs should be analyzed.

According to INCIBE, Keeping perimeter protection systems up to date and periodically reviewing their configuration is one of the most effective measures to reduce the risk of suffering a cybersecurity incident.

In Apen We offer a comprehensive firewall implementation and management service. This includes network architecture design, device configuration, continuous monitoring, and preventative maintenance. If you'd like to learn how to improve your company's firewall deployment, call us at 938 606 220 or check out our cybersecurity services.

Frequently Asked Questions

What factors determine the deployment of firewalls in a company?

The number of devices, network complexity, traffic volume, and level of risk exposure are the main factors. A company with multiple locations or cloud environments will need a more complex setup than a business with a single office.

Should a company's firewall system include internal firewalls?

In robust architectures, yes. In addition to the perimeter firewall, it is recommended to segment the internal network with additional firewalls. These protect sensitive areas such as database servers or production systems.

What happens if a company's firewall deployment is insufficient?

The standard requires the designation of clear roles and responsibilities, usually through an Information Security Officer, although the commitment should involve the entire organization, including management.

What happens if a certified company experiences a security incident?

Yes. In addition to the physical perimeter, it's necessary to control traffic to and from cloud services. This involves complementing the traditional firewall with security solutions specifically designed for SaaS and remote access environments.

How can I tell if my company's firewall setup is adequate?

The most reliable way is to conduct a perimeter security audit. This evaluates the current architecture, identifies weaknesses, and proposes specific improvements. At Apen, we perform this analysis free of charge and without obligation.

29/07/2026