BLOG
Firewall Basics for Small Businesses
The front door
A firewall is not antivirus with a scarier name. It is the device that decides what is allowed in and out, and which parts of your network are allowed to talk to each other. A lot of South Jersey shops are still using the ISP gateway as that device, with default passwords, UPnP on, and every camera, guest phone, and accounting PC in one flat LAN. That works until it does not. When it does not, the blast radius is the whole office.
We set and support cybersecurity and firewall plant from Mays Landing. The basics are not a SOC we pretend to run, and they are not a compliance binder we do not run. They are: a real firewall, admin that is not “admin/admin,” WAN rules that are not wide open, and VLANs so cameras and guests cannot browse staff files.
Cameras and guests off staff files
Guest Wi-Fi is hospitality. It is also a room full of devices you do not patch. Camera systems are another room of devices, often with vendor defaults and a cloud relay. Neither belongs on the same network as the shared folder and the front-desk PC. Segmentation is a few VLANs and firewall rules, not a new company. If a camera is compromised, it should see other cameras and the NVR — not the bookkeeper’s desktop.
The same idea applies to a smart TV in the lobby and a vendor laptop that “just needs the Wi-Fi.” Give them a guest path. Do not give them the staff SSID because it was faster that afternoon. The afternoon you save is the afternoon you spend later explaining a ransomware note.
Admin that is not default
Change the firewall admin password. Put MFA on that login if the device supports it. Stop exposing the admin page to the whole internet because someone wanted to “check it from home” without a VPN or a known jump path. Firmware updates are part of the same boring list as endpoint patching. None of this is exciting. All of it is the difference between a contained incident and a bad week.
An ISP gateway is a modem with a LAN port. It is not a firewall you can stand on. Default Wi-Fi on that box, remote admin from the WAN, and UPnP punching holes for a camera app are the usual plant we find in a Mays Landing or island closet. Replacing it with a real appliance is only half the job. The other half is the rules: which VLAN may talk to which, whether the owner reaches admin through a known path, and whether last year’s port-forward for a vendor still exists. We will show you the rules in English, not a screenshot of a thousand lines.
Izzo Network, Mays Landing, NJ. Call 609-415-0011 if you want the front door looked at — the actual appliance in the rack, not a slide about zero trust. We will tell you whether you have a firewall or a router with a marketing sticker.
Izzo Network
Mays Landing, NJ
