Skip to main content
Fortinet & Sophos Enterprise Firewall & BGP Solutions

Enterprise Firewall and Cybersecurity Solutions

For national and international projects, we plan enterprise firewall, BGP routing, peering, multi-ISP, VPN, IPS/IDS, web/application control and network segmentation. Where endpoint protection is required, EDR/XDR is integrated as a separate technical scope.

Endpoint Security Integration

A Dedicated Technical Scope for Antivirus, EDR & XDR

This page focuses on network security. For endpoint security, EDR/XDR selection, pilot migration and operating model, use our dedicated technical page.

5651 Logging & Data Protection Technical Controls

Protect Against Penal Liabilities
Time-Stamped Full Legal Logging

We build logging infrastructures designed to retain access records under Law No. 5651 in line with the relevant business model and applicable requirements. Technical requirements such as time stamping, integrity and access control are planned according to project scope.

Ransomware Prevention

Don't Let Your Files Get Encrypted
Multi-Layer Ransomware Protection

We defend your company's commercial data, accounting records, and customer info against lock-outs and blackmail attempts with a multi-layered security architecture.

Why Doz Technology Cybersecurity Consulting?

We don't just sell boxes; we design an end-to-end protection shield covering your network, endpoints, and employees.

Proactive Threat Prevention

We proactively block malware and intrusion attempts at the network perimeter (Firewall) before they infect your systems.

Legal & Regulatory Compliance

We build logging infrastructures by considering data-security measures under KVKK and relevant technical requirements under Law No. 5651. The scope of legal compliance should be assessed separately according to the organization’s activities and applicable obligations.

Layered Security with Endpoint Protection

The firewall controls network traffic, while endpoint security adds behavioral visibility on user and server endpoints. We address EDR/XDR selection as a separate technical scope.

Review the Antivirus, EDR & XDR technical scope

Secure VPN & Multi-Factor Auth

We implement mandatory SSL VPN and Two-Factor Authentication (MFA/2FA) for personnel connecting remotely to the corporate network.

Web & Application Management

We enhance both network security and business productivity by restricting malicious sites, social media, and bandwidth-consuming apps.

Experienced Security Team

With our team experienced in Fortinet and Sophos products, we provide support for contracted organizations within the SLA defined in the applicable agreement.

Expert Cybersecurity Services

Professional solutions in Fortinet, Sophos, EDR/XDR antivirus, 5651 legal logging, DLP, and penetration testing.

NGFW Firewall & BGP Setup

Supply, rule configuration, BGP dynamic routing, and management of Fortinet FortiGate, Sophos XGS, and SonicWall firewall devices.

  • IPS/IDS Intrusion Prevention & BGP Routing
  • Deep Packet Inspection (DPI) & Peering

Endpoint Security Integration

We connect firewall architecture with endpoint security, MFA and backup layers; product selection and the operating model are covered on the dedicated EDR/XDR page.

Review the Antivirus, EDR & XDR technical scope

5651 Legal Logging & Hotspot

Time-stamped access logging compliant with Law 5651 and SMS-verified guest Wi-Fi (Hotspot) integration.

  • TÜBİTAK Time Stamp Signature
  • SMS OTP Integration Module

SSL VPN & Multi-Factor Auth

Access to company resources for remote personnel via secure IPsec/SSL VPN and SMS/OTP 2FA authentication.

  • 256-bit Encrypted Tunneling
  • Mobile Authenticator Integration

Data Loss Prevention (DLP)

Preventing the leakage of sensitive company data, customer lists, and financial documents via USB, email, or the cloud.

  • USB Blocking & Content Scanning
  • Sensitive Data Protection Policies

Web Filtering & Bandwidth

Category-based web content blocking, application control, and prioritizing company internet traffic (QoS).

  • Malicious & Phishing Block
  • YouTube / Social Media Restriction

Security Layers That Reduce Ransomware Risk

An active shield that detects and instantly stops the file encryption engines of ransomware and restores files to their original state.

  • Crypto-Locking Detection
  • Auto Shadow Copy Restore

Cybersecurity Analysis & Pentest

Penetration tests and detailed reporting that detect vulnerabilities in your network, servers, and security devices.

  • Internal & External Vuln. Scan
  • Executive Security Report

Enterprise Firewall Solutions

We evaluate firewall selection together with user count, internet capacity, branches, VPN architecture, security services, high availability and the existing network topology.

Fortinet FortiGate Firewall Solutions

For FortiGate projects we plan sizing, security policies, NAT, VLAN/segmentation, IPS, web and application control, site-to-site or remote-access VPN and, when required, HA according to project scope.

Sophos XGS Firewall Solutions

For Sophos XGS projects we analyze the existing network and configure WAN/LAN, NAT, security policies, segmentation, VPN, IPS, web filtering and application control according to requirements.

BGP Routing, Peering & Multi-WAN Security

For multi-homed ISP connections, we configure BGP (Border Gateway Protocol) dynamic routing, Peering integration and prefix filtering policies on your firewall to ensure automatic failover, latency optimization and secure WAN traffic flow.

Endpoint Security Integration

We plan access, isolation and incident-response workflows between the firewall and endpoint layer. Antivirus, EDR and XDR details are covered on the dedicated endpoint-security page.

Review the Antivirus, EDR & XDR technical scope

Layered Security to Reduce Ransomware Risk

No single firewall or antivirus product eliminates ransomware risk. Firewall, EDR/XDR, MFA, network segmentation, patch management and isolated/immutable backup layers should be considered together.

Read the Ransomware Protection and Response Guide

Our Firewall Installation and Configuration Process

1. Discovery & Analysis

We identify user, traffic, WAN, branch, VPN, VLAN and critical application requirements.

2. Sizing

We determine device capacity, security services, licensing and high-availability requirements.

3. Installation & Migration

We configure policies, NAT, VPN and segmentation and execute a controlled migration plan.

4. Testing & Management

We test access, complete the documentation and activate the management/support plan within the agreed scope.

Firewall Sales, Licensing and Management

We evaluate appliance, security subscription/license, installation, migration and support according to actual capacity and security requirements.

Factors That Determine Firewall Pricing

User count, internet capacity, VPN, IPS, web filtering, HA, license term and support scope affect pricing.

License Renewal & Maintenance

We evaluate security subscriptions, license terms, maintenance and technical support requirements according to the existing product and contract scope.

Firewall Management with MSP

For organizations that require ongoing management, we can handle firewall operations Managed IT Services (MSP) as part of our managed IT services.

PURCHASING & ARCHITECTURE

6 Decisions That Should Not Be Missed in a Firewall Quote

Before choosing a model, clarify how security services affect performance, management, licensing and migration.

Threat-Protection Performance

Evaluate expected traffic capacity with IPS, web filtering, application control and, where required, TLS/SSL inspection enabled.

SD-WAN & Multiple Links

For multiple internet links or branches, plan failover, application-aware routing and SD-WAN from the start.

Central Management & Logging

For multiple devices or sites, evaluate centralized policy, configuration, log analysis and reporting.

Licensing & Lifecycle

Subscription scope, support term, firmware lifecycle and service life are part of total cost of ownership.

HA Is Not DR

HA can improve availability during appliance failure, but it is not disaster recovery by itself. Links, power, site dependency and configuration backup must be addressed separately.

Migration & Rollback Plan

When migrating NAT, VLAN, VPN, routing and policies, document the maintenance window, test scenario and rollback steps.

NGFW SIZING

Firewall Sizing Should Use Security Throughput, Not Only Internet Speed

NGFW selection should consider enabled security services, concurrent sessions, VPN usage, WAN links and expected growth. A device that matches raw interface speed may become a bottleneck when IPS, web filtering and SSL inspection are active.

Sizing Inputs

  • Internet and inter-site link speeds
  • Concurrent users, sessions and VPN load
  • IPS, application control, web filtering and SSL inspection
  • HA, SD-WAN, BGP and future capacity needs

Firewall & Cybersecurity Frequently Asked Questions

Frequently asked questions about firewall selection, FortiGate, Sophos XGS, VPN, licensing and network-security architecture.

What is a firewall and why should businesses use one?

A firewall is a security layer that controls network traffic according to defined security policies. It helps reduce the risk of unauthorized access and malicious network traffic.

Do you provide firewall installation?

Yes. Depending on the project scope, we carry out discovery, sizing, product and license procurement, installation, configuration, testing and commissioning.

Do you install Fortinet FortiGate?

Yes. Based on requirements, we configure FortiGate sizing, security policies, NAT, VLAN, IPS, web and application control, VPN and HA components.

Do you install Sophos XGS Firewall?

Yes. In Sophos XGS projects, we configure WAN/LAN, NAT, security policies, segmentation, VPN, IPS, web filtering and application control according to the project scope.

FortiGate mi Sophos XGS mi tercih edilmeli?

There is no single correct choice. Traffic capacity, user count, existing infrastructure, required security services, management model, licensing and total cost of ownership should be evaluated together.

How are BGP Routing and Peering managed on a Firewall?

For multi-homed ISP connections, BGP dynamic routing and peering rules configured on NGFW devices ensure automatic failover, latency optimization, and BGP hijacking protection.

How is firewall pricing determined?

Pricing varies according to device capacity, user and traffic requirements, security subscriptions, VPN, HA, license term, installation and support scope.

What is an NGFW?

A next-generation firewall (NGFW) can combine advanced security functions such as IPS, application control and web filtering on a single platform in addition to traditional traffic control.

Can a firewall stop ransomware attacks by itself?

No. A firewall is an important security layer, but reducing ransomware risk also requires additional controls such as EDR/XDR, MFA, segmentation, patch management and secure backups.

Should MFA be used for VPN access?

MFA adds an additional authentication layer if a password is compromised and helps reduce remote-access risk. We recommend evaluating it together with VPN access where appropriate.

What is the difference between IPS and IDS?

IDS focuses on detecting suspicious traffic and generating alerts, while IPS can block detected traffic depending on policy and configuration.

Can web and application filtering be configured on a firewall?

On suitable NGFW platforms, category-based web filtering, application control and traffic policies can be applied. Available features vary by device and license scope.

Can our existing firewall be replaced?

Yes. Before migration, existing rules, NAT, VPN, VLANs, service dependencies and downtime tolerance should be analyzed and a controlled migration plan prepared.

Can a firewall be managed remotely?

Remote management is possible with appropriate security policies and an authorization model. Controls such as restricting management access, MFA and logging should also be evaluated.

Is Law No. 5651 logging applied the same way to every business?

No. Applicable obligations may vary depending on the organization’s activities and relevant legislation. Doz Technology designs the technical logging infrastructure; this statement is not legal advice.

Review a sample technical project scenario for this solution
Review the enterprise firewall selection guide
Message on WhatsApp Call Now
Copied!