Managed Firewall Service

The goal of the managed service is to take away the burden of managing the firewall on a day to day basis, and the need for the partner to have a specific skillset and the time required to manage these complex devices in a GCSx restrictive environment.

The solution will utilise EAL4 approved Cisco ASA firewall devices located at the partner site. The service includes initial configuration, monitoring, and ongoing management of the devices. Where required the solution can also be deployed as a resilient pair improving availability.

The monitoring portion of this service is summarised as:

  • 24 x 7 monitoring of the firewall device – 5 minute poll period
  • Telemetry and reporting from the device displayed and reported 24 x 7 via the NOC portal
  • Syslog capture to the central KPSN syslog
  • Break / fix maintenance with 4 hour equipment replacement

The management portion of the service is summarised as:

  • 1st, 2nd, and 3rd level support of the service and configuration
  • Rulebase and configuration changes in line with the size of partner and deployment (reasonable amounts of MACs (moves, adds, changes))
  • Best practice guidance and security advice for new rulebase additions
  • Regular housekeeping reviews and GCSx compliance advise
  • Dispatch of Unisys field service technicians where required

Service Pricing

  • The service will be priced according to the size of the partner or KPSN entity, and mapped into a small, medium, or large model.
  • The sizing will be derived from a combination of the number of users within the partner, how complex the DMZ front-end is, and how many MACs and rulebase changes are expected.

Technical details of the Managed Firewall Service