Managed Next-Gen Firewall
Next-generation firewall as a service on Fortinet, Palo Alto Networks or Check Point - IPS, URL filtering, sandboxing and application control, with policy management, change control, high availability and reporting run by Dollu 24×7.

3
Vendor platforms to choose from
4 h
Standard change turnaround
99.99%
HA pair availability SLA
What is Managed Next-Gen Firewall?
Dollu Managed Next-Gen Firewall delivers enterprise firewalling as a fully managed service. You choose the platform - Fortinet FortiGate, Palo Alto Networks or Check Point - and the deployment model: physical or virtual appliances at your sites, virtual firewalls hosted at Dollu PoPs in the path of your MPLS, SD-WAN or DIA traffic, or cloud-native instances in Dollu Cloud, AWS, Azure or Google Cloud. Dollu designs, deploys, licenses, monitors, patches and operates the estate, and your team retains full visibility through the portal and vendor consoles.
The security stack goes well beyond port and protocol rules. Application identification and user-based policy, intrusion prevention with daily signature updates, URL and DNS filtering, TLS inspection with certificate management, cloud sandboxing for unknown files, anti-malware, DNS security and IoT device visibility are configured according to a hardened baseline and then tuned to your traffic. Segmentation between user, server, guest, OT and payment zones is designed with you and enforced consistently across every firewall in the estate.
Operations are the point of a managed service. Every policy change goes through a change-control process with peer review, scheduled implementation, verification and rollback; standard changes are completed within four business hours and emergency changes within one hour, 24×7. Firmware and signature updates are staged and applied in your maintenance windows. Firewalls are monitored continuously for health, throughput, session counts and HA state, and every security event feeds Dollu MDR and SOC or your own SIEM for correlation.
Reporting turns firewall logs into decisions. Monthly reports cover blocked threats by category, top applications and users, URL filtering activity, IPS events, rule usage and unused rules, configuration drift and compliance posture against CIS benchmarks and frameworks such as PCI-DSS and ISO 27001. Quarterly reviews with your named security engineer clean up rule bases, retire shadowed rules and align policy with business change, so the firewall estate stays tidy rather than accumulating exceptions.
Why choose Dollu for managed firewall.
The advantages of buying from a carrier that owns its network, interconnects and operations - rather than a reseller.
Enterprise firewalling without the headcount
Certified Fortinet, Palo Alto and Check Point engineers on a 24×7 rota handle policy, patching, licensing and incidents, so your team is not paged for firmware upgrades or rule requests.
Change control that is fast and safe
Peer-reviewed changes with defined turnaround, verification and rollback keep the estate consistent and auditable while still moving at business speed.
Consistent policy everywhere
One policy model across branches, data centres, PoP-hosted firewalls and cloud instances, so a rule change is applied once and enforced consistently.
Threat visibility you can act on
Monthly reporting on blocked threats, applications, users and rule usage, with events correlated in Dollu MDR or your SIEM, so the firewall becomes a sensor as well as a control.
Fits your network, not the other way round
Firewalls placed on premises, in the Dollu core or in cloud depending on traffic flows, integrated with Dollu SD-WAN, MPLS and DIA so security follows the topology.
Capabilities in detail.
Everything included with Managed Next-Gen Firewall - the platform features, options and controls you get from day one.
- 01
Multi-vendor NGFW platforms
Fortinet FortiGate, Palo Alto Networks PA-Series and VM-Series, Check Point Quantum and CloudGuard; hardware, virtual and cloud form factors; licences and support bundled or bring-your-own.
- 02
Threat prevention stack
Intrusion prevention, anti-malware, cloud sandboxing for unknown files, URL and DNS filtering, TLS/SSL inspection, application control, DNS security, botnet and C2 blocking, IoT and OT device identification.
- 03
Deployment options
Customer-premises appliances, virtual firewalls hosted at Dollu PoPs in-line with MPLS, SD-WAN or DIA, and cloud instances in Dollu Cloud, AWS, Azure or Google Cloud with centralised management.
- 04
High availability and scale
Active/passive or active/active clusters, dual power and dual uplinks, session synchronisation and stateful failover; capacity from branch appliances to multi-10G data-centre and 100G core firewalls.
- 05
Policy and change management
Baseline hardening, segmentation design, request portal, peer review, scheduled implementation with verification and rollback; standard changes in 4 business hours, emergency in 1 hour, 24×7.
- 06
Lifecycle operations
Firmware and signature staging and rollout in maintenance windows, licence and certificate renewal, configuration backup and drift detection, capacity monitoring and hardware RMA handling.
- 07
Monitoring and event integration
24×7 health and performance monitoring, syslog and API streaming of security events to Dollu MDR/SOC or your SIEM, alerting on threshold breaches and HA state changes.
- 08
Reporting and reviews
Monthly threat, application, user and rule-usage reports; compliance posture against CIS, PCI-DSS and ISO 27001; quarterly rule-base clean-up and policy review with a named security engineer.
- 09
Remote access and site-to-site VPN
IPsec site-to-site tunnels to partners and clouds, and client VPN with MFA where ZTNA has not yet replaced it, managed on the same firewalls with the same change process.
How it works.
From first conversation to live traffic - a tracked, engineer-led onboarding with a named owner at every step.
- Step 01
Assess and design
We review sites, traffic flows, existing rule bases and compliance requirements, recommend platform, sizing and placement, and produce a segmentation and policy design.
- Step 02
Deploy
Appliances are staged and shipped or virtual instances are provisioned, HA pairs are built, existing rules are migrated and cleaned, and cutover is scheduled per site.
- Step 03
Tune
IPS, application control and TLS inspection run in monitor mode first, then move to block as false positives are cleared. Reporting and SIEM integration are verified.
- Step 04
Operate
24×7 monitoring, change control, patching, licence management and monthly reporting, with quarterly reviews to keep the rule base clean and policy aligned to the business.
Who uses this and why.
Typical deployments across carriers, enterprises, platforms and contact centres.
Multi-site enterprises
Consistent NGFW policy across headquarters, branches and data centres, with PoP-hosted firewalls securing SD-WAN and MPLS internet breakout centrally.
Retail and hospitality chains
PCI-DSS segmentation of payment traffic from guest Wi-Fi and back-office systems at hundreds of sites, with centrally managed changes and audit-ready reports.
Healthcare
Segmentation of clinical, administrative, guest and medical-device networks, sandboxing of email attachments and downloads, and TLS inspection with exemptions for sensitive categories.
Manufacturing and OT
Industrial firewalls between IT and OT zones with protocol-aware policies for Modbus, DNP3 and OPC UA, and strict change control for plant environments.
Financial services
Data-centre and cloud firewalls with active/active HA, full logging retention, rule-base hygiene evidence and quarterly reviews aligned to RBI and ISO 27001 audits.
Technical & commercial specifications.
Key parameters at a glance. Ask us for the full service description and SLA document.
| Platforms | Fortinet FortiGate; Palo Alto PA/VM-Series; Check Point Quantum/CloudGuard |
|---|---|
| Form factors | Hardware, virtual, cloud; branch to 100G core |
| Placement | Customer premises, Dollu PoPs, Dollu Cloud, AWS, Azure, GCP |
| Security functions | IPS, AV, sandboxing, URL/DNS filtering, TLS inspection, app control |
| High availability | Active/passive or active/active; 99.99% pair availability SLA |
| Change SLA | Standard 4 business hours; emergency 1 hour, 24×7 |
| Updates | Signatures daily; firmware staged in agreed maintenance windows |
| Event integration | Syslog/API to Dollu MDR/SOC or customer SIEM |
| Reporting | Monthly threat, usage, rule-hygiene and compliance reports |
| Support | 24×7 security operations; P1 response ≤ 15 min; named engineer |
How Security is priced.
Security services are priced per protected site or circuit, per user or per endpoint - and MDR by endpoint count or log volume. Assessments and penetration tests are fixed-scope projects.
We publish the model, not a public rate card - actual rates depend on destination, route class, volume and regulatory cost. See how every Dollu service is priced.
- DDoS and managed firewall per protected site or circuit
- SASE and zero trust per user
- MDR per endpoint or by log volume
- Assessments and penetration tests as fixed-scope projects
- 12–36 month terms on managed services
- Billing
- Monthly recurring in advance; projects invoiced on milestones
- Commitment
- 12–36 months for managed services; none for assessments
Managed Firewall - your questions answered.
The questions customers and carriers ask us most often before they interconnect. If yours is not here, our team answers within one business day.
Still have a question?
Ask our solutions teamRelated services.
Services customers commonly combine with Managed Next-Gen Firewall.
Hand us your firewalls.
Share your site list, current platform and throughput and we will return a platform recommendation, placement design and monthly pricing within two business days.
