Firewall as a Service in India — Managed NGFW on Subscription

  • Home
  • Firewall as a Service in India — Managed NGFW on Subscription
Firewall as a Service in India — Managed NGFW on Subscription
Firewall as a Service in India — Managed NGFW on Subscription
Firewall as a Service in India — Managed NGFW on Subscription
Firewall as a Service in India — Managed NGFW on Subscription

Firewall as a Service

Firewall as a ServiceA firewall you never have to buy, size or babysit

Firewall as a Service means the appliance, the licences, the tuning and the round-the-clock watch arrive as one monthly line item instead of a capital purchase and a hiring problem. P J Networks sizes it against your real traffic, runs it from our Delhi NOC and SOC, and stays accountable for how it behaves in production — not just for shipping the box.

ISO/IEC 27001:2022 certified · NOC and SOC in Mayapuri, New Delhi · operating enterprise firewalls since 2002

The part vendors gloss over

Two different things are sold as “Firewall as a Service”

The term covers two architectures that solve different problems, and a lot of comparison articles quietly mix them. Knowing which one you are being quoted is the whole decision, because they differ on where inspection happens, what leaves your premises, and what still works when the link goes down.

Traffic path in cloud-delivered FWaaS versus managed on-premises FWaaSIn cloud-delivered FWaaS, branch traffic crosses the internet to a provider point of presence where inspection happens, then reaches the application. If the WAN link drops, no inspected path exists. In managed on-premises FWaaS, inspection happens on an appliance at the branch before traffic reaches the internet, so local policy is still enforced when the WAN link drops.MODEL A — CLOUD-DELIVERED FWAASYour branchusers, LANPublic internetuninspected legProvider PoPinspection hereApps, SaaSdestinationWAN link drops → there is no inspected path at all. Users are offline, or they bypass.MODEL B — MANAGED ON-PREMISES FWAAS (WHAT WE RUN)Your branchusers, LANNGFW on siteinspection herePublic internetalready filteredApps, SaaSdestinationWAN link drops → the LAN keeps running and local policy is still enforced on the box.

Where inspection sits is the decision. Everything else follows from it.

Cloud-delivered FWaaS

Inspection happens in the provider’s cloud. You point traffic at their point of presence and policy is applied there. This is the model Zscaler, Cato Networks, Palo Alto Prisma Access and Cloudflare sell, usually inside a broader SASE or SSE platform. It suits a distributed, cloud-first estate with a large remote workforce and little left in a data centre.

We will say the honest thing here rather than the convenient one: if that describes you, a cloud-native FWaaS platform is probably the better architecture, and we will tell you so. We are not going to sell you an appliance to solve a problem that no longer sits behind one.

These platforms are usually sold as SASE or SSE rather than as a firewall on its own, which makes like-for-like comparison harder than it looks. FWaaS vs SASE vs SWG sets out what each term actually covers and what to ask a vendor.

Managed on-premises FWaaS

The firewall is a next-generation appliance at your edge, but you consume it as a service: no capital purchase, no sizing gamble, no in-house firewall engineer. The hardware, licences, configuration, change control, firmware and 24×7 monitoring are one recurring cost, and the operator is accountable for the outcome. This is what most Indian enterprises with real on-premises infrastructure, plant networks, regulated data or unreliable branch links actually need — and it is what we run.

Choosing between them

Which model fits your estate

An honest decision aid rather than a scorecard we always win. Most estates are mixed, and the answer is often both — a cloud service for roaming users and an inspected edge where the infrastructure actually lives.

If this describes you Better fit Why
Mostly SaaS, staff working anywhere, nothing much in a data centre Cloud-delivered FWaaS There is no edge left to inspect at. Backhauling to an appliance adds latency for no gain.
Factory, warehouse, hospital or campus with equipment that never leaves the site Managed on-premises FWaaS OT and local traffic never touch the internet, so cloud inspection never sees it.
Branches on links that degrade or drop Managed on-premises FWaaS Local policy survives the outage. A cloud-only path does not.
Data residency or sector rules that constrain where traffic and logs may go Managed on-premises FWaaS Inspection and logs stay in your jurisdiction by construction, not by contract clause.
Large remote workforce, few fixed sites Cloud-delivered FWaaS Policy follows the user rather than the office.
Existing appliances mid-life, but no one to run them Managed on-premises FWaaS Keep the investment, hand over the operating burden.

Scroll to see the full table →

Scope, stated plainly

Who owns what

The commonest failure in a managed firewall contract is not technical. It is a boundary nobody wrote down, discovered during an incident. This is ours.

Responsibility split between your team, P J Networks and the firewall vendorAcross sizing, supply, business policy, day-to-day changes, monitoring, firmware and hardware failure, P J Networks owns the operational work. Your team owns business policy decisions and change approvals. The vendor manufactures, publishes signatures and honours warranty.LIFECYCLE STAGEYOUR TEAMP J NETWORKSVENDORSizingMeasures real throughput, specifiesSupply and licencesProcures, owns, renewsManufacturesBusiness policyDecides who reaches whatTranslates it into rulesDay-to-day changesApprovesImplements, logs, backs out24×7 monitoringWatches, triages, escalatesFirmware and signaturesTests, schedules, appliesPublishesHardware failureSwaps it, coordinates RMAHonours warranty

You keep the decisions that are yours to make. We keep the work.

The monthly line item

What is actually included

01

The appliance, sized properly

Specified against measured throughput with inspection switched on — not the datasheet maximum, which is quoted with most of the security features off. High availability pairs where the site warrants one.

02

Licences and subscriptions

IPS, application control, web filtering, anti-malware and sandboxing bundled into the same recurring cost, renewed by us. No lapse because a renewal PO sat unsigned.

03

Configuration and migration

Policy built from your actual traffic rather than copied forward. If you are moving off an existing box, see firewall migration services.

04

Change control

Every rule change requested, reviewed, applied and logged, with a backout position before it goes in. Changes are the commonest cause of self-inflicted outages.

05

24×7 monitoring from our NOC and SOC

The box is watched by named engineers on a real roster, not polled by a script nobody reads. Detections land in the same queue as the rest of your estate.

06

Firmware, failover and replacement

Patching on a tested schedule, failover proven rather than assumed, and hardware swapped when it dies. This is the ongoing half people forget to price — see firewall AMC.

From the field

What actually goes wrong with firewalls

Almost nothing we are called to fix is a product defect. The box does what it was told. The problem is what it was told, by whom, and how long ago — and that is an operating problem, which is precisely what a service model is supposed to absorb.

Rules nobody dares delete

Policies accumulate for years. Permissive rules added “temporarily” during a migration outlive the person who added them, because no one can prove what will break. A rule review finds them — see firewall audit and rule review.

Sized on a datasheet number

Throughput figures are published with inspection largely disabled. Turn on the features you bought the box for and real capacity falls sharply. Undersized boxes then get “fixed” by switching inspection off, which defeats the purchase.

Firmware left where it shipped

Deferred because nobody owns the maintenance window, until a disclosed vulnerability makes it urgent and unplanned. A service contract makes the window somebody’s job.

Logs going nowhere

Logging enabled, retention never configured, nothing forwarded off the box. The evidence you need during an incident aged out weeks earlier. Ours forward into a monitored platform by default.

Failover that has never been tested

An HA pair is an assumption until somebody pulls a cable in a maintenance window. Plenty of pairs fail over in theory and not in practice.

Nobody watching out of hours

A firewall that alerts into an unwatched mailbox is a speed bump. Detection without a roster behind it is not a control.

Commercials

Service, rental or purchase

Three ways to end up with a working firewall. They differ in who carries the capital, the risk and the operating burden — not in the quality of the protection, provided somebody competent is running it.

Buy outright Rental Firewall as a Service
Upfront cost Full capital purchase None None
Who owns the hardware You Us Us
Licences and renewals Your responsibility Included Included
Configuration and changes Your team, or per-incident help Available as an add-on Included, under change control
24×7 monitoring Only if you staff it Included with our rentals Included
Firmware and failover testing Your responsibility Shared Ours
Sizing risk Yours — a wrong call is a write-off Ours — we swap the model Ours — we swap the model
Best when You have a firewall team and want the asset You want kit without capital You want the outcome, not the device

Scroll to see the full table →

Not sure which way to go? Firewall rental versus purchase works through the commercial case, and our guide to NGFW sizing and real throughput covers how to specify the box itself. For one-off implementation and AMC work rather than a full service, see firewall services. For what drives the number on a quote, see firewall as a service pricing in India.

Delivered by P J Networks

A firewall still needs somebody awake

We deploy it, tune it to your traffic, and then operate it 24×7 from our own ISO/IEC 27001:2022 certified NOC and SOC in Mayapuri, New Delhi — by named engineers who already know your environment. Doing that since 2002.

Sized on measurement

Scoped from your real traffic with inspection on, not a datasheet maximum.

Multi-vendor

FortiGate, Cisco, Palo Alto, Sophos and Check Point — specified on fit, not on what we hold.

Co-managed or fully managed

Keep console access and let us work the queue, or hand over the lot.

Evidence for the auditor

Change logs, retained firewall logs and reporting aligned to CERT-In, RBI, SEBI and DPDP expectations.

The firewall feeds the same platform as the rest of your estate. Our security operations centre works its detections and our network operations centre watches its availability, so a saturated link and a blocked intrusion are visible as one picture rather than two tickets.

Questions we get asked

Firewall as a Service, answered

What does FWaaS mean?

Firewall as a Service (FWaaS) means consuming firewall protection as an operating subscription rather than buying and running a device. In the cloud-delivered sense it means inspection happens in a provider’s cloud. In the managed sense it means an appliance sits at your edge but the provider owns the hardware, licences, configuration and 24×7 operation. Both remove the capital purchase; only one removes the on-site device.

How is FWaaS different from an NGFW?

They are not alternatives. An NGFW is the technology — a firewall that inspects applications, users and content rather than just ports and addresses. FWaaS is a delivery and commercial model for getting one. You can buy an NGFW outright, rent it, or consume it as a service; it is the same class of technology in each case.

Is FWaaS the same as SASE or SSE?

No, though they are related. SASE and SSE are broader platforms that bundle several security functions — secure web gateway, zero-trust access, CASB and a cloud firewall among them — delivered from the same cloud. Cloud FWaaS is usually one component inside such a platform. If a vendor is selling you SASE, the firewall is part of a much larger commitment, which is worth knowing before you compare it to an appliance quote.

What is the difference between FWaaS and a secure web gateway?

A secure web gateway inspects web traffic specifically — HTTP and HTTPS, URL filtering, malware in downloads. A firewall covers all traffic and protocols, not just browsing. In cloud platforms the two functions increasingly sit side by side, but a gateway alone will not police the non-web traffic a firewall handles.

How is it priced?

Per site and per appliance class, driven by the throughput you actually need with inspection enabled and which subscriptions you require, on a committed term. We publish no list price because a number quoted before anyone has measured your traffic is a guess, and the usual result of guessing is an undersized box with its security features turned down to cope. We size first, then quote.

Can you take over the firewalls we already own?

Yes, and that is a common starting point. We audit the existing rule base, document what is actually in force, agree what to remove, and then operate the box under change control. You keep the asset you paid for and hand over the work. If the hardware is genuinely end of life we will say so rather than nurse it.

Will our logs and traffic stay in India?

With the managed on-premises model, inspection happens on your site and logs land where we configure them to land, so keeping both in Indian jurisdiction is straightforward. Cloud-delivered platforms depend on where the provider’s points of presence and log stores sit, which is a question worth asking them directly. We will configure retention to the obligations that apply to you, but compliance remains your legal posture — no product or service makes an organisation compliant on its own.

What happens when the internet link fails?

With an appliance on site, the LAN keeps working and local policy is still enforced; only internet-bound traffic is affected, and a second link can fail over automatically. With a cloud-only inspection path there is no protected route while the link is down, which is why branch sites on unreliable connectivity usually want inspection locally.

Get it sized before you get it quoted

Tell us what runs at each site and how the links behave. We will measure what you actually push, tell you which delivery model fits — including when it is not ours — and put a number against it.