palmiq Speak to an expert

Firewall Modernization for Government Contractors

7 min read

Comparing FortiGate models for a CUI environment? Here are the four criteria that matter: segmentation, encrypted inspection, audit evidence, and availability.

From below of long thin blue cables connected to row of small white connectors on system block in data center

If you are reading this, you have probably already made the decision. The firewall at the edge of your network is the oldest piece of infrastructure in the building, it is at or near end-of-support, and someone — a prime, an assessor, an insurance underwriter, or your own team — has asked a question about it that you could not answer cleanly.

So this is not an argument that you need a new firewall. It is a set of criteria for choosing one, written for contractors who handle CUI and live with NIST 800-171, CMMC, and in many cases GCC High.

palmiq is a Fortinet partner, so we will use FortiGate as the reference platform. We will also be specific about what we are not doing: we are not quoting throughput, TLS inspection rates, session counts, or license bundle contents in this post. Those numbers are model-specific, they shift sharply depending on which inspection profiles you turn on, and the only defensible source for them is Fortinet’s current published datasheet for the exact model you are pricing. Any vendor or MSP who quotes you a performance number without naming the model and the inspection profile behind it is doing you a disservice.

Your firewall was specified for a network that no longer exists

The perimeter box you bought six or eight years ago was scoped for a network where most of your work happened on managed laptops inside one office, most traffic was unencrypted enough to be useful to a stateful filter, and your CUI lived on a file server down the hall.

That network is gone. You now have remote engineers, a cloud tenant holding controlled data, SaaS tools in the delivery path, shop floor or lab equipment that nobody is allowed to patch on your schedule, subcontractors who need narrow access, and traffic that is encrypted almost end to end. The firewall did not fail. Its assumptions did.

Consideration-stage buyers usually do not need convincing on that point. What they need is a way to compare platforms on the four things that actually determine whether the replacement holds up.

What the current threat data says

Two figures are worth putting on the table before the criteria.

IBM’s 2025 Cost of a Data Breach Report found that roughly 1 in 6 breaches involved attackers using AI, most commonly for phishing (37%) and deepfake impersonation (35%). The same report put the average cost of an extortion or ransomware incident at $5.08 million, and found that 63% of organizations refused to pay ransom demands, up from 59% the prior year — while fewer victims involved law enforcement, despite evidence in the report that doing so reduces costs.

One caveat, stated plainly: we sourced these figures from a third-party summary of IBM’s report rather than from IBM directly. We cite them as IBM’s findings, and we would encourage you to read IBM’s primary report before you put any of these numbers in a board deck.

What they tell you about firewall selection is narrow but useful. Initial access is increasingly delivered through convincing human-facing lures, not through unauthenticated services exposed at the edge. That means the value of a modern firewall sits less in blocking inbound scans and more in what it does with outbound and lateral traffic: DNS and web filtering, inline inspection of encrypted sessions, and enough visibility to correlate with your email and endpoint telemetry.

1. Segmentation: keep the CUI boundary small

Segmentation is the control that determines blast radius. Whether an incident is contained to one VLAN or walks the whole network is usually decided by network architecture, not by detection speed.

For a contractor, the segmentation conversation is also a scoping conversation. A well-defined enclave for CUI — separated from general corporate IT, from guest wireless, and from unmanaged equipment — reduces the number of systems in assessment scope. That is a compliance benefit and a cost benefit at the same time.

Questions to ask when comparing platforms:

  • How many separate policy domains can the platform enforce, and does the model you are pricing support the segmentation design you actually want?
  • Can you write policy by identity and device rather than only by IP range?
  • What happens to unmanaged equipment you are not permitted to patch, scan aggressively, or reconfigure? Segmentation and monitoring are the realistic compensating controls there, not remediation.
  • Can the same policy model extend to a second site or a cloud environment without a separate management approach?

2. Encrypted inspection without wrecking performance

If most of your traffic is encrypted and your firewall cannot inspect it at a workable rate, then your filtering, application control, and threat feeds are only seeing envelopes.

This is where old hardware quits. It is also where vendors’ marketing numbers get slippery, because inspection throughput drops significantly once you enable decryption plus application control plus intrusion prevention plus logging.

Ask for the specific datasheet figure for the model under consideration, with the inspection profile named. Then ask what happens to your latency-sensitive workloads — CAD sessions, large file transfers, virtual desktops, engineering tools — under that profile. Then decide where you will not decrypt, and write that decision down as policy, because you will be asked to explain it.

3. Evidence, not just protection

The part of the purchase most buyers underestimate is what happens after installation.

Assessors do not accept “we have a next-generation firewall.” They ask what the boundary is, how policy is documented and approved, what is logged, how long logs are retained, who reviews them, and what happens when something is flagged. Cyber insurance questionnaires ask a similar set of questions in different language.

So evaluate the management and logging layer as seriously as you evaluate the hardware. Can you produce a readable policy export? Can you show change history with approvals? Can you retain and search logs for the period your obligations require? Can you generate a report that answers an underwriter’s question without a week of manual work?

Two things we will not claim: no firewall makes an organization CMMC-ready or NIST 800-171 compliant. Compliance is an organizational program — risk assessment, policy, workforce training, incident response, supplier flow-down. A modern firewall supports specific technical controls within that program and produces evidence for them. And deploying a particular firewall does not lower your insurance premium or secure coverage; underwriting criteria vary by carrier. What better logging does is improve the quality of the answers you can give.

4. Availability: a firewall outage is a delivery event

In a contracting environment, an edge device failure is not an IT ticket. It stops billable work, it stops secure file exchange with a prime, and if it happens during a milestone week it becomes a program conversation.

Price high availability from the start. Ask what failover looks like in practice, how firmware updates are staged and rolled back, and what the maintenance window discipline is going to be. A design that can only be updated by taking the boundary down will not get updated.

Recoverability is part of the firewall strategy

Given the ransomware figures above, prevention alone is not the posture. Tested recovery is what turns an extortion demand into a decision rather than a crisis.

palmiq is an Acronis Platinum partner (top 1% globally) and a Veeam partner, so we tend to look at the firewall and the recovery plan in the same conversation — including whether your backups are segmented away from the network they protect, and whether a restore has actually been tested recently rather than assumed.

It has to fit the stack you already have

Firewall replacement is a good moment to check whether the layers around it are coherent. palmiq works across Fortinet for the edge, Ruckus for wireless, Microsoft for identity and productivity including GCC High environments, CrowdStrike and SentinelOne for endpoint, Sophos, AWS and Google Workspace, and Acronis and Veeam for backup and recovery. We are Microsoft Gold and hold WOSB and EDWOSB status, which matters to some contracting officers as a procurement pathway.

Owning a next-generation firewall versus operating one

The gap between the two is policy tuning, firmware lifecycle management, log review, and someone watching at 2 a.m. palmiq runs a 24/7 SOC with a 15-minute response SLA on critical issues. Within our MDR and EDR services specifically, we maintain a 99.9% threat neutralization rate and neutralize 1,200-plus threats monthly.

If you are comparing FortiGate models right now, the useful next step is a short conversation about your segmentation design, your inspection tolerance, and your evidence obligations — before the model gets chosen, because those three things determine the model.

Book a discovery call with palmiq.

Want this handled for you?

We run managed IT, security and backup for organizations that would rather not read another article about it.

Speak to an expert

or call 703-336-9700