How to Choose a Business Firewall Without Wasting Budget
How to choose a business firewall that truly protects: real throughput, UTM vs NGFW, licences and HA explained for SMEs. Practical criteria and pitfalls.

In this article
- What a business firewall actually is (and why the router's isn't enough)
- UTM and NGFW: the two terms you need to know
- The practical criteria for choosing a business firewall
- The most common mistakes we see in SMEs
- The firewall does not work alone
- Let's choose the right firewall for your business together
To choose a business firewall, start from real-world throughput with every security control switched on (not the headline spec sheet figure), the number of users and sites you need to protect, and the security features you genuinely require: application filtering, IPS, VPN, web control and perimeter antivirus. Then weigh up licences, high availability and who will manage the appliance over time.
What a business firewall actually is (and why the router's isn't enough)
A business firewall is the appliance that filters all traffic between your internal network and the outside world, deciding what gets in and what goes out. It is not the small firewall built into your broadband router: that does basic gatekeeping, but it does not inspect content, does not recognise applications and does not stop modern threats.
A business-class firewall works at a far deeper level. It does not just look at ports and IP addresses; it understands which application is generating the traffic (is that genuinely web browsing, or malware hiding on port 443?), inspects content for malicious code, and applies different rules by department, user or device. It is the difference between a turnstile that counts people and a security officer who knows who is walking through and what they are carrying.
In our hands-on work with SMEs across Lombardy, the firewall is often the most underrated part of the infrastructure. Companies invest sensibly in servers and backups, then leave an ageing appliance in production with expired licences and firmware frozen three years in the past. That is precisely where most of the incidents we are called in to handle begin.
UTM and NGFW: the two terms you need to know
Anyone comparing quotes runs into two acronyms straight away. They are worth clarifying, because they drive both the price and the capability of the appliance.
UTM (Unified Threat Management)
A UTM concentrates several security functions into a single device: firewall, perimeter antivirus, web content filtering, anti-spam, VPN and IPS. It is the "all-in-one" approach, designed specifically for small and medium businesses that cannot manage ten separate boxes. The upside is simplicity; the catch is that switching on every module at once drags performance down.
NGFW (Next-Generation Firewall)
An NGFW puts application awareness and user identity at its core. It can tell Facebook apart from a web-based business application even when both travel over the same encrypted port, it integrates an advanced IPS (Intrusion Prevention System) and, in most cases, HTTPS traffic inspection. In practice the UTM/NGFW line has blurred: most SME firewalls now offer both approaches. What matters is understanding which modules you will actually use and at what cost to performance.
The practical criteria for choosing a business firewall
These are the parameters we weigh up with clients when there is an appliance to size. They are listed in order of importance.
1. Real throughput, not the headline figure
This is mistake number one. Data sheets quote a sky-high "firewall throughput", but that figure is measured with no security controls active. The moment you turn on IPS, antivirus and HTTPS inspection, usable bandwidth can collapse by 70-80%.
The figure that counts is the Threat Protection throughput (or "NGFW throughput" with every module active). Compare it against your connectivity bandwidth and your real traffic peaks. A firewall that chokes a 1 Gbit fibre line does not protect you: it just slows you down, and sooner or later someone disables the controls "because the network is crawling". At that point you have paid for security you are not using.
2. Number of users, devices and sites
Sizing starts with how many people and how many devices pass through the appliance, including IP phones, cameras, printers and IoT devices. If you run multiple sites, look at its ability to sustain stable site-to-site VPNs and a healthy number of client VPN tunnels for remote working. Under-sizing here means buying twice within a year.
3. The security features you actually need
Not every module is useful to every business. The ones that matter most for an SME:
- Application Control: blocks or throttles specific applications (streaming, personal cloud storage, unsanctioned tools).
- IPS: detects and stops attempts to exploit known vulnerabilities.
- Web filtering: filters sites by category, cutting phishing and distraction.
- Perimeter antivirus and sandboxing: analyse attachments and downloaded files before they reach the endpoints.
- SSL/TLS inspection: looks inside encrypted traffic, where most threats now hide. Be warned: this is the feature that weighs most heavily on performance.
- Access control and segmentation: separate networks for offices, production, guests and IoT.
4. VPN and secure remote access
With hybrid working now the norm, the VPN has become a critical function. Check support for modern protocols, integration with multi-factor authentication (MFA) and the option to apply Zero Trust logic. Remote access without MFA is a door left wide open.
5. High availability and long-term management
If the firewall fails, the business is cut off from the internet and often grinds to a halt. For organisations that cannot absorb downtime, an HA (High Availability) setup with two appliances in redundancy is not a luxury. Then consider reporting, ease of management and, above all, who will keep the appliance up to date: firmware, IPS signatures, rules. A firewall is only alive if someone tends it. This ties directly into our managed IT security for businesses, where firewall, backup and monitoring work as one.
6. Licences and total cost
The hardware price is only the beginning. Almost every vendor sells the security modules as an annual subscription (often bundled over 1, 3 or 5 years). A cheap firewall with expensive licences can cost more over three years than a higher-tier model. Always reason in terms of TCO (total cost of ownership) over 3-5 years, licences and support included.
The most common mistakes we see in SMEs
Some errors recur with striking regularity:
- Buying on the headline throughput and ending up with a slow network once controls are switched on.
- Letting licences lapse: a firewall with out-of-date IPS and antivirus signatures protects about as well as a 2019 antivirus.
- "Any-any" rules never cleaned up: permissive configurations left in place for years that undermine the whole appliance.
- No segmentation: IP cameras and business applications on the same flat network, so one compromised device reaches everything.
- No continuity plan: a single firewall with no redundancy and no spare unit.
On these points, a periodic infrastructure assessment makes the difference between owning a firewall and actually having protection.
The firewall does not work alone
A good firewall is necessary but not sufficient. It is part of a wider strategy that includes tested, immutable backups, patched systems, MFA on access and continuous monitoring. It is precisely on monitoring that we built Hector, our AI-based platform that keeps an eye on servers and network appliances, spots anomalies and flags suspicious behaviour before it becomes an incident. Because even the best-configured firewall needs watching: logs are worth little if no one reads them in time.
Let's choose the right firewall for your business together
Choosing a business firewall is not settled by picking the cheapest data sheet: it is settled by sizing the appliance to your real traffic, your sites and the threats you need to stop. For more than 25 years we have supported SMEs in Melzo and across Lombardy in protecting networks and servers, with the pragmatism of a team that actually does the maintenance (ISO 9001 and 27001 certified, Google 4.7/5 across 37 reviews).
Call TN Solutions on 02 9517550 for advice on the firewall best suited to your network, or get in touch via our contact page. We will analyse your infrastructure and tell you, with the data in front of us, what you need and what you do not.
Frequently asked questions
How much does a business firewall cost for an SME?
It depends on the sizing. For a small company with 10-25 workstations, the hardware starts at a few hundred euros, but the real cost lies in the multi-year security licences and support. Reason in terms of total cost over three years: a mid-range model with licences included often works out cheaper than an entry-level unit with separate subscriptions.
UTM or NGFW: which is better?
For most SMEs the distinction now matters little: nearly every modern appliance offers both UTM functions (all-in-one) and NGFW capabilities (application and user awareness). The right question is not "which acronym", but "which modules will I switch on, and with what impact on performance".
Isn't my router's firewall enough?
No, not for a business. The firewall built into your broadband router does basic filtering on ports and addresses, but it does not inspect content, recognise applications or stop advanced malware and phishing. You need a dedicated appliance with up-to-date security modules.
How often should a firewall be updated?
The security signatures (IPS, antivirus, web categories) update automatically several times a day, provided the licence is active. Firmware should be updated as soon as security patches are released. The hardware is generally reviewed every 4-5 years, or when your connectivity bandwidth outgrows what the appliance can handle with the controls active.
Do I need two firewalls in high availability?
You do if losing the internet connection halts business operations. An HA setup with two appliances ensures that, if one fails, the second takes over automatically. For smaller organisations, a pre-configured spare unit can be a workable alternative.
Technology partners
Want to discuss it with our team?
We analyse your infrastructure for free and propose the most suitable solution.







