Home / Case Studies / Corporate Firewall
Case Study · Property & Construction · Corporate Firewall · FortiGate

An Australian property and construction group strengthened its corporate network edge with a managed FortiGate firewall deployment

The group operates a distributed operating environment. It depends on secure access to Microsoft 365, business-critical operational workflows, project information, consultant collaboration and executive workflows every day — so the corporate firewall could not be treated as a simple perimeter appliance. It needed to support secure connectivity, user access, branch and site traffic, VPN requirements, Microsoft 365 performance, threat prevention and ongoing manageability.

Inlight IT delivered a corporate firewall deployment for the group, aligned to a cyber-first managed IT model. The focus was not only installation — it was to create a supportable firewall environment with clearer policy control, stronger perimeter protection, managed access pathways and a better operating foundation for future network and SD-WAN requirements.

OUTSIDEINSPECTIONINSIDE MANAGED EDGE / INSPECTION INSPECTIONPOLICYACCESSSERVICES PROPERTY & CONSTRUCTION / CORPORATE FIREWALL FORTIGATE / POLICY · ACCESS · SERVICES
Engagement at a glance

An Australian property and construction group — corporate firewall deployment and managed network security

A more supportable FortiGate firewall environment for secure access, site connectivity, remote and third-party access governance, Microsoft 365 traffic and perimeter control.

Client
Australian property and construction group
Industry
Property and construction
Region
Australia
Environment
A distributed operating environment carrying Microsoft 365, business-critical operational workflows and project information
Engagement
Corporate firewall deployment and managed network security — establish a more supportable firewall environment for secure internet access, site connectivity, remote and third-party access governance, Microsoft 365 traffic and perimeter control
Operating model
Cyber-first managed IT, with the FortiGate firewall inside the managed support rhythm
Outcome
A managed firewall platform supporting stronger perimeter security, clearer traffic control, controlled remote access and improved network supportability
Key project stats

One FortiGate platform, five delivery workstreams

Multi-site
users supported

Corporate network security aligned to a distributed property development and construction operating environment.

5
delivery workstreams

Firewall deployment, policy and traffic control, threat prevention, remote and third-party access governance, and ongoing managed operation.

1
managed FortiGate platform

A single corporate firewall platform treated as a security control, not a hardware installation.

M365
cloud traffic considered

Microsoft 365 and cloud application access treated as part of the firewall and network design, not generic internet traffic.

Operating context

A corporate firewall is the control point between the business, the internet, cloud platforms, users and remote access

The group's technology environment had to support a busy, distributed operating model: users across a distributed operating environment, business-critical operational workflows, consultant communication and Microsoft 365 collaboration.

In that context, firewall deployment needed to do more than restore internet connectivity. It needed to provide a cleaner security and network control point: policy, inspection, remote and third-party access governance, logging, firmware lifecycle, cloud traffic handling and future network changes.

Inlight IT treated the deployment as a managed firewall and network security project, not a hardware installation.

What made it important

The group needed a firewall environment that could support a distributed operating environment, not just protect a single office connection

The firewall needed to support secure business operations across users, locations, applications and external dependencies. The key risk was not only whether traffic could pass through the firewall — it was whether the environment would remain secure, visible and supportable after deployment.

01

The firewall had to support multiple business workflows

The group depends on email, project documents, business-critical operational workflows, consultant communication and executive access. Firewall policy had to support these workflows without creating avoidable performance or access issues.

02

Microsoft 365 and cloud traffic needed practical handling

Microsoft 365 traffic behaves differently from traditional on-premises application traffic. Poor firewall and routing decisions show up as Teams performance, file access and mail latency, so the edge had to support cloud-first productivity without unnecessary backhaul or policy friction.

03

Remote and site access needed stronger control

Users working across a distributed operating environment require controlled access pathways. Remote and third-party access governance needs proper policy, MFA alignment, user control and review — and a platform ready for ZTNA where the identity and application model justifies it.

04

Firewall rules needed an operating model

Rules accumulate over time: temporary access, project requirements, third-party access, application exceptions and legacy rules. Without review the firewall becomes harder to manage and less defensible, so the deployment needed a cleaner operating baseline.

05

Firmware and security services needed ownership

Protection depends on more than the appliance. FortiGuard services, IPS signatures, firmware cadence, SSL inspection decisions and alert review all require ownership — a deployed firewall without lifecycle management becomes a future exposure.

What Inlight IT delivered

A managed corporate firewall deployment aligned to the group’s users, sites, applications and security posture

Inlight IT delivered the firewall project around five practical workstreams: firewall design and deployment, policy and traffic control, threat prevention and FortiGuard services, remote and third-party access governance, and ongoing managed operation.

01

Firewall design and deployment

The firewall was deployed as a production security control, not simply a replacement appliance — reviewed and deployed around the traffic patterns, access requirements and support needs of the business.

Included
Corporate firewall deploymentInternet edge & traffic flow reviewFirewall policy baselineNAT & routing considerationsMigration & rollback planningProduction cutover support
02

Policy, rules and traffic control

Firewall rules were structured around business access requirements and supportability — a clearer policy foundation for allowed traffic, blocked traffic, remote access, internet access, cloud application access and business system dependencies.

Included
Firewall rule review & implementationPolicy aligned to business useRemoval of unnecessary open pathsApplication control considerationsLogging & visibilityRule documentation & handover
03

Threat prevention and FortiGuard services

FortiGate value depends on how its security services are configured and managed. The deployment was aligned to practical threat-prevention controls, with attention to performance, inspection depth and operational support.

Included
FortiGuard subscription awarenessIPS & application controlWeb filtering considerationsDNS security considerationsSSL inspection decision pathwayFirmware & patch cadence
04

Remote and third-party access governance

Remote access was treated as an access-control problem, not only a connectivity feature — supporting users outside the office while keeping access appropriately controlled.

Included
Remote & third-party access reviewMFA & identity alignmentRemote user access policyThird-party / contractor accessSegmentation & least privilegeZTNA readiness where appropriate
05

Managed firewall operation

After deployment the firewall was brought into the managed IT rhythm — operational ownership, review and escalation so it would not become unmanaged perimeter infrastructure.

Included
Firewall monitoring considerationsFirmware lifecycle reviewFortiGuard renewal awarenessPolicy change managementIssue escalationService review alignment
Delivery approach

From current-state review and FortiGate deployment through to ongoing managed operation

Select a stage to trace how the firewall moved from deployment to managed operation.

Market context

The network edge is now a priority attack surface

Firewall, VPN and perimeter devices are no longer background infrastructure — attackers actively target edge devices because they can provide initial access, credential capture, configuration exposure and lateral movement pathways. For an organisation of this kind, the firewall protects the network path behind sales activity, finance workflows, project records, settlement communication, remote access and Microsoft 365 connectivity: a board-level cyber risk, not a network-engineering footnote.

22%

Of vulnerability exploitation actions targeted edge devices and VPNs in 2025 — an almost eightfold rise from 3% the previous year.

54%

Of exploited edge-device vulnerabilities were fully remediated, with a median remediation time of 32 days.

1,700+

Times the ACSC notified Australian entities of potentially malicious cyber activity — an 83% increase year on year.

Verizon 2025 Data Breach Investigations ReportASD Annual Cyber Threat Report 2024–25
What changed for the client

The group gained a more supportable corporate firewall environment for users, sites, cloud services and secure access

The deployment gave the group a stronger firewall operating baseline — easier to support, easier to review and better aligned to the business's security, network and access requirements.

O·01

Perimeter security

A clearer control point for internet access, inbound and outbound traffic, remote access and perimeter policy.

O·02

Policy control

Firewall policy managed with clearer structure, reducing unmanaged rules, unclear exceptions and unnecessary access paths.

O·03

Cloud productivity

Microsoft 365 traffic treated as part of the firewall and network operating model, not as generic internet traffic.

O·04

Remote access

Access reviewed against identity, MFA, user access and future ZTNA suitability.

O·05

Managed operation

Firmware cadence, security services, rule review, escalation and improvement became part of ongoing IT management.

O·06

A supportable baseline

A cleaner operating baseline so rules, policies and exceptions can be managed properly over time.

Net position

The strongest firewall deployment is not the one that finishes at cutover — it is the one that remains controlled after the first change request.

Proof from the work

A corporate firewall treated as a managed security and network control point

Outcome 01

Distributed environment

Corporate network security aligned to a distributed operating environment.

Outcome 02

FortiGate managed platform

Deployment structured around security, traffic control, policy and ongoing ownership.

Outcome 03

M365 cloud traffic considered

Microsoft 365 and cloud access considered as part of the firewall and network design.

Outcome 04

Cyber-first perimeter control

Firewall, access, firmware, rules, remote access and posture treated as managed disciplines.

Outcome 05

Remote access pathway

Remote access, MFA and ZTNA suitability considered as part of the access model.

Outcome 06

Managed lifecycle

Firmware cadence, FortiGuard services, rule review and escalation brought into managed IT.

Engineering-led, cyber-first

The work connected firewall and edge, threat prevention, network and access, and lifecycle and operations

Firewall & edge

4
  • FortiGate firewall deployment
  • Corporate firewall policy
  • Internet edge security
  • Firewall rule review

Threat prevention

3
  • FortiGuard services
  • IPS & application control
  • SSL inspection decision pathway

Network & access

4
  • NAT & routing
  • Remote & third-party access
  • Microsoft 365 traffic considerations
  • Network & SD-WAN readiness

Lifecycle & operations

2
  • Firmware lifecycle review
  • Managed firewall operation
Practical next step

Need a firewall deployment that stays managed after cutover?

We review firewall policy, access and lifecycle, then manage the environment after cutover.

Discuss Firewall Review