An Australian property and construction group strengthened its corporate network edge with a managed FortiGate firewall deployment
The group operates a distributed operating environment. It depends on secure access to Microsoft 365, business-critical operational workflows, project information, consultant collaboration and executive workflows every day — so the corporate firewall could not be treated as a simple perimeter appliance. It needed to support secure connectivity, user access, branch and site traffic, VPN requirements, Microsoft 365 performance, threat prevention and ongoing manageability.
Inlight IT delivered a corporate firewall deployment for the group, aligned to a cyber-first managed IT model. The focus was not only installation — it was to create a supportable firewall environment with clearer policy control, stronger perimeter protection, managed access pathways and a better operating foundation for future network and SD-WAN requirements.
- Client
- Australian property and construction group
- Industry
- Property and construction
- Region
- Australia
- Environment
- A distributed operating environment carrying Microsoft 365, business-critical operational workflows and project information
- Engagement
- Corporate firewall deployment and managed network security — establish a more supportable firewall environment for secure internet access, site connectivity, remote and third-party access governance, Microsoft 365 traffic and perimeter control
- Operating model
- Cyber-first managed IT, with the FortiGate firewall inside the managed support rhythm
- Outcome
- A managed firewall platform supporting stronger perimeter security, clearer traffic control, controlled remote access and improved network supportability
An Australian property and construction group — corporate firewall deployment and managed network security
A more supportable FortiGate firewall environment for secure access, site connectivity, remote and third-party access governance, Microsoft 365 traffic and perimeter control.
One FortiGate platform, five delivery workstreams
Corporate network security aligned to a distributed property development and construction operating environment.
Firewall deployment, policy and traffic control, threat prevention, remote and third-party access governance, and ongoing managed operation.
A single corporate firewall platform treated as a security control, not a hardware installation.
Microsoft 365 and cloud application access treated as part of the firewall and network design, not generic internet traffic.
A corporate firewall is the control point between the business, the internet, cloud platforms, users and remote access
The group's technology environment had to support a busy, distributed operating model: users across a distributed operating environment, business-critical operational workflows, consultant communication and Microsoft 365 collaboration.
In that context, firewall deployment needed to do more than restore internet connectivity. It needed to provide a cleaner security and network control point: policy, inspection, remote and third-party access governance, logging, firmware lifecycle, cloud traffic handling and future network changes.
Inlight IT treated the deployment as a managed firewall and network security project, not a hardware installation.
The group needed a firewall environment that could support a distributed operating environment, not just protect a single office connection
The firewall needed to support secure business operations across users, locations, applications and external dependencies. The key risk was not only whether traffic could pass through the firewall — it was whether the environment would remain secure, visible and supportable after deployment.
The firewall had to support multiple business workflows
The group depends on email, project documents, business-critical operational workflows, consultant communication and executive access. Firewall policy had to support these workflows without creating avoidable performance or access issues.
Microsoft 365 and cloud traffic needed practical handling
Microsoft 365 traffic behaves differently from traditional on-premises application traffic. Poor firewall and routing decisions show up as Teams performance, file access and mail latency, so the edge had to support cloud-first productivity without unnecessary backhaul or policy friction.
Remote and site access needed stronger control
Users working across a distributed operating environment require controlled access pathways. Remote and third-party access governance needs proper policy, MFA alignment, user control and review — and a platform ready for ZTNA where the identity and application model justifies it.
Firewall rules needed an operating model
Rules accumulate over time: temporary access, project requirements, third-party access, application exceptions and legacy rules. Without review the firewall becomes harder to manage and less defensible, so the deployment needed a cleaner operating baseline.
Firmware and security services needed ownership
Protection depends on more than the appliance. FortiGuard services, IPS signatures, firmware cadence, SSL inspection decisions and alert review all require ownership — a deployed firewall without lifecycle management becomes a future exposure.
A managed corporate firewall deployment aligned to the group’s users, sites, applications and security posture
Inlight IT delivered the firewall project around five practical workstreams: firewall design and deployment, policy and traffic control, threat prevention and FortiGuard services, remote and third-party access governance, and ongoing managed operation.
01Firewall design and deployment
The firewall was deployed as a production security control, not simply a replacement appliance — reviewed and deployed around the traffic patterns, access requirements and support needs of the business.
02Policy, rules and traffic control
Firewall rules were structured around business access requirements and supportability — a clearer policy foundation for allowed traffic, blocked traffic, remote access, internet access, cloud application access and business system dependencies.
03Threat prevention and FortiGuard services
FortiGate value depends on how its security services are configured and managed. The deployment was aligned to practical threat-prevention controls, with attention to performance, inspection depth and operational support.
04Remote and third-party access governance
Remote access was treated as an access-control problem, not only a connectivity feature — supporting users outside the office while keeping access appropriately controlled.
05Managed firewall operation
After deployment the firewall was brought into the managed IT rhythm — operational ownership, review and escalation so it would not become unmanaged perimeter infrastructure.
From current-state review and FortiGate deployment through to ongoing managed operation
Select a stage to trace how the firewall moved from deployment to managed operation.
The network edge is now a priority attack surface
Firewall, VPN and perimeter devices are no longer background infrastructure — attackers actively target edge devices because they can provide initial access, credential capture, configuration exposure and lateral movement pathways. For an organisation of this kind, the firewall protects the network path behind sales activity, finance workflows, project records, settlement communication, remote access and Microsoft 365 connectivity: a board-level cyber risk, not a network-engineering footnote.
Of vulnerability exploitation actions targeted edge devices and VPNs in 2025 — an almost eightfold rise from 3% the previous year.
Of exploited edge-device vulnerabilities were fully remediated, with a median remediation time of 32 days.
Times the ACSC notified Australian entities of potentially malicious cyber activity — an 83% increase year on year.
The group gained a more supportable corporate firewall environment for users, sites, cloud services and secure access
The deployment gave the group a stronger firewall operating baseline — easier to support, easier to review and better aligned to the business's security, network and access requirements.
Perimeter security
A clearer control point for internet access, inbound and outbound traffic, remote access and perimeter policy.
Policy control
Firewall policy managed with clearer structure, reducing unmanaged rules, unclear exceptions and unnecessary access paths.
Cloud productivity
Microsoft 365 traffic treated as part of the firewall and network operating model, not as generic internet traffic.
Remote access
Access reviewed against identity, MFA, user access and future ZTNA suitability.
Managed operation
Firmware cadence, security services, rule review, escalation and improvement became part of ongoing IT management.
A supportable baseline
A cleaner operating baseline so rules, policies and exceptions can be managed properly over time.
The strongest firewall deployment is not the one that finishes at cutover — it is the one that remains controlled after the first change request.
A corporate firewall treated as a managed security and network control point
Distributed environment
Corporate network security aligned to a distributed operating environment.
FortiGate managed platform
Deployment structured around security, traffic control, policy and ongoing ownership.
M365 cloud traffic considered
Microsoft 365 and cloud access considered as part of the firewall and network design.
Cyber-first perimeter control
Firewall, access, firmware, rules, remote access and posture treated as managed disciplines.
Remote access pathway
Remote access, MFA and ZTNA suitability considered as part of the access model.
Managed lifecycle
Firmware cadence, FortiGuard services, rule review and escalation brought into managed IT.
The work connected firewall and edge, threat prevention, network and access, and lifecycle and operations
Firewall & edge
4- FortiGate firewall deployment
- Corporate firewall policy
- Internet edge security
- Firewall rule review
Threat prevention
3- FortiGuard services
- IPS & application control
- SSL inspection decision pathway
Network & access
4- NAT & routing
- Remote & third-party access
- Microsoft 365 traffic considerations
- Network & SD-WAN readiness
Lifecycle & operations
2- Firmware lifecycle review
- Managed firewall operation
Need a firewall deployment that stays managed after cutover?
We review firewall policy, access and lifecycle, then manage the environment after cutover.
Discuss Firewall Review