Skip to main content
ALL PRODUCTS 20% OFF THROUGH 9/30 · APPLIED AT CHECKOUT

deployment

SMB Firewalla Deployment for SOHO Clients

The 3D Rack Mounts team

Every MSP has a tier of client that does not fit the standard build. Six to twenty seats, one office, no server room — just a closet with a modem, a switch, and whatever the last guy left behind. They cannot justify a managed firewall with a four-figure annual subscription, but the compliance questionnaire from their largest customer now asks whether they have network-level threat detection, and "the ISP router has a firewall in it" is no longer an answer anyone accepts.

Firewalla lives squarely in that gap. It is a consumer-priced appliance with a feature set that overlaps a real SMB firewall in the places that matter for this client size, and it costs less per year than most vendors charge for a support renewal. It is also, in several specific ways, not an enterprise product, and deploying it as though it were will cost you support hours later. This post is the deployment playbook: when to reach for it, which model, how to place it in the topology, and how to get it into a tight closet without it looking like a hobby project.

The mount for this build:

19" Firewalla Gold SE Rack Mount - 1U (Modular)

When Firewalla is the right call — and when it isn't

The case for Firewalla at a SOHO client is economic before it is technical. The hardware is a one-time cost in the range of a few hundred dollars, and the core feature set — IDS/IPS-style blocking, per-device rules, VPN server, VLAN support, and continuous traffic visibility — carries no mandatory recurring license. For a ten-seat client who balks at any new monthly line item, that pricing structure is what gets the deal signed. There is an optional cloud service tier for extended history and some managed features, but the box does its primary job without it.

The technical case is narrower but real. Firewalla's traffic visibility is unusually good for the price. You get per-device flow history, DNS-level insight, and alerting that is specific enough to act on, all through an interface a non-technical office manager can actually look at without being trained. When a client calls because "the internet is slow," being able to name the device and the destination in ninety seconds is worth something.

Where it stops being the right call:

  • Regulated environments with an auditor. If the client is subject to a framework that expects documented firewall change control, formal support SLAs, and vendor security attestations, Firewalla will not survive the questionnaire. Do not try to make it.
  • Multi-site clients needing consistent policy. Firewalla can build site-to-site tunnels, but there is no real multi-tenant management plane. Three sites means three apps' worth of state in your head.
  • Anything above roughly 25–30 active users. Not because the hardware falls over, but because the management model — a phone app tied to an account — does not scale to a network where multiple technicians need coordinated access.
  • Clients who need RADIUS, complex NAT, or BGP. Wrong product category entirely.

The gotcha that catches MSPs first: Firewalla's administration is mobile-app-centric. There is a web interface now, and it has improved considerably, but the app remains the primary surface and it is bound to an account. Decide up front whose account owns the box, document it, and put it in your offboarding checklist. An MSP that loses access to a client's firewall because a technician left with the account on their personal phone has created a problem that no amount of physical access solves quickly.

Model selection for the SOHO tier

The lineup splits cleanly by throughput and port configuration, and picking correctly is mostly about matching the client's WAN speed with a bit of headroom for inspection overhead.

Firewalla Purple sits at the entry point for anything you would call a business deployment. It is a small unit with a pair of gigabit ports and onboard Wi-Fi, rated in the several-hundred-megabit range with inspection enabled. For a client on a 200–300 Mbps cable circuit with a dozen devices, it is sufficient and it is cheap. The onboard Wi-Fi is not something you should plan a business network around — treat it as a bonus or a backup AP, not as coverage.

Firewalla Gold SE is the one that fits most SOHO deployments correctly. Four ports, multi-gigabit-capable, fanless, and rated well above gigabit for inspected throughput. Fanless matters more than the spec sheet suggests when the appliance is going into a closet next to somebody's desk. For a client with a gigabit fiber circuit, the SE is the model that will not become the bottleneck the week after you install it.

Firewalla Gold Plus steps up to 2.5G ports across the board and higher inspection throughput. Reach for it when the client has a multi-gig circuit, when you need more than one high-speed LAN segment, or when there is a plausible path to a faster circuit within the equipment's life. It runs warmer than the SE, which is a placement consideration rather than a dealbreaker.

Above that sits the Gold Pro and the rack-form Firewalla hardware, which are generally past the point where this article's client profile applies.

A sizing note worth saying out loud: vendor throughput figures for any inspecting firewall are best-case numbers under synthetic load. Assume real-world inspected throughput lands meaningfully below the headline, and size so that the client's contracted circuit speed is comfortably under it. A firewall that becomes the bottleneck is a support ticket that never fully goes away, because the client will forever associate the slowdown with the thing you installed.

Topology patterns that work

Three deployment patterns cover nearly every SOHO install.

Pattern one: full gateway replacement. The ISP device goes into bridge or pass-through mode, the Firewalla takes the public IP, and it handles NAT, DHCP, and routing for the whole site. This is the correct default. It gives you a single, coherent address plan and puts the inspection engine in the path of everything. The friction is entirely with the ISP — some carriers make bridge mode a phone call, and some make it an ordeal. Find out before you schedule the cutover, not during it.

Pattern two: double NAT, deliberately. When bridge mode is unavailable or the ISP device is doing something you cannot remove — carrier voice service is the usual culprit — you leave the ISP router as the edge and put the Firewalla behind it as the LAN gateway. You accept double NAT, put the ISP router's LAN on a small dedicated subnet, and move on. Inbound services get more complicated and you should note it in the documentation, but for a client whose only inbound need is a VPN, the practical cost is low.

Pattern three: simple mode / transparent bridge. Firewalla can sit inline between the existing router and the switch without taking over routing at all. This is the fastest install and the one that preserves the existing network exactly, which makes it attractive for a client who is nervous about change. It also gives up most of the segmentation value, since you are not the DHCP server or the routing boundary. Use it as a proof-of-value install with a plan to convert to pattern one, not as a permanent state.

Whichever pattern you choose, segment something on day one. Even a minimal split — staff devices on one VLAN, the guest Wi-Fi and the printer and the smart TV in the conference room on another — converts the Firewalla from a monitoring appliance into an actual security control. The clients most likely to be compromised at this size are the ones where the receptionist's phone is on the same flat /24 as the accounting workstation.

Rack and closet placement

The physical install is where a SOHO Firewalla deployment either looks professional or looks like a home project, and the difference is almost entirely about whether the appliance is mounted or merely present.

The default state of an unmounted Firewalla is: sitting on top of the modem, resting on its own cables, in a closet with a shelf that is 300 mm deep and full of something else. That arrangement fails in predictable ways. Cable weight drags the unit toward the edge. Somebody moves it to get at the modem and does not put it back. It ends up on its side, blocking the vents, in a closet that is already the warmest room in the suite.

Mounting solves all of that at once, and the form factor question comes down to what is already in the closet.

If the client has a full-depth 19-inch rack or a wall-mount 19-inch enclosure — increasingly common even in small offices — a 1U mount is the obvious answer. A rack unit is 44.45 mm per EIA-310-D, and the Gold SE and Gold Plus both fit within that height lying flat, so you get the appliance, its ears, and nothing wasted. A modular 1U panel is worth specifying here because it lets you put the firewall and a second small device in the same rack unit, which matters when the whole closet is 6U.

If the closet has a 10-inch cabinet — the half-width format that has become the sane default for offices with one closet and no floor space — the same logic applies at a smaller scale. A 10-inch 1U mount holds the Firewalla at the same height and leaves the rest of the cabinet for the switch and the patch panel.

Either way, three placement rules earn their keep:

  • Put the firewall above the switch, below the modem. It follows the logical path, which means the jumper cables are short and the next technician can read the rack without a diagram.
  • Leave a vented U above a Gold Plus. It runs warmer than the SE and closets stack heat toward the top. A blanking panel with vents costs almost nothing and buys thermal margin you cannot add later.
  • Service loop every cable and strain-relieve behind the mount. The single most common cause of an intermittent WAN at a small site is a patch cable under tension in a closet where the door hits the rack.

One more thing on the fanless models specifically: fanless means convection, and convection means the case is the heatsink. Do not stack anything on top of a Gold SE and do not mount it flush against a solid panel. It will work — and then it will throttle in August, and you will spend an afternoon on it.

Handover and documentation

The Firewalla install is not finished when the traffic flows. For a client relationship you intend to keep, three things need to exist in writing.

First, the ownership record: which account the box is bound to, who has the app installed, and what the recovery path is. Second, the network map — VLANs, subnets, DHCP scopes, and any rule that a future technician would find surprising. Firewalla's rule engine allows some very specific per-device behavior, and a rule created to fix one printer in 2026 is indistinguishable from a mystery in 2029 unless somebody wrote it down. Third, the escalation boundary: what this appliance does not do, so that when the client's insurer or a customer's security team asks, the answer is prepared rather than improvised.

Set the client's expectations on updates too. Firewalla pushes firmware fairly regularly, and the default is to apply them. That is usually the right posture at this client size, but it means an unattended change window exists on the client's network. Either accept that and say so, or take manual control of it and own the patch cadence yourself. The failure mode is the middle position, where nobody is managing updates and everybody assumes somebody is.

Wrap-up

Firewalla earns its place in an MSP's catalog as the answer to a specific question: what do you put in front of a ten-seat office that needs real segmentation and real visibility but cannot carry an enterprise firewall's cost or complexity. Pick the Gold SE for most gigabit sites and the Gold Plus when the circuit or the segmentation demands more. Replace the ISP gateway if the carrier will let you, accept double NAT if it will not, and segment something on day one regardless.

Then mount it. A firewall lying on top of a modem is a firewall that will move, overheat, or get unplugged, and none of those are problems worth billing against. Fifteen minutes and a 1U mount converts the install from something the client tolerates into something they point at when a customer asks about their security posture.

Mounts in this build

Not sure which mount you need?

Search by device and we'll show the mount that fits it.

Find my mount →