---
title: "Business network protection | Avepto"
canonical_url: "https://avepto.ch/en/cybersecurity/networks"
last_updated: "2026-09-13T20:46:37.072Z"
meta:
  description: "Managed firewall, segmentation and continuous monitoring. A reliable network depends on suitable hardware, current rules and a support team you can reach."
  "og:description": "Managed firewall, segmentation and continuous monitoring. A reliable network depends on suitable hardware, current rules and a support team you can reach."
  "og:title": "Business network protection"
  "twitter:description": "Managed firewall, segmentation and continuous monitoring. A reliable network depends on suitable hardware, current rules and a support team you can reach."
  "twitter:title": "Business network protection"
---

# Knowing what flows across your network.

Without monitoring, your company’s traffic stays a blind spot. Avepto watches your firewall, spots the unusual and explains what matters.

Book a network audit

![Fortinet](https://avepto.ch/_nuxt/fortinet.BVt7gKvL.svg)![pfSense](https://avepto.ch/_nuxt/pfsense.xpCI-k1l.svg)![Ubiquiti UniFi](https://avepto.ch/_nuxt/unifi.DNiLZRSL.svg)![TP-Link Omada](https://avepto.ch/_nuxt/omada.ErQfaGf6.svg)

![Fortinet](https://avepto.ch/_nuxt/fortinet.BVt7gKvL.svg)![pfSense](https://avepto.ch/_nuxt/pfsense.xpCI-k1l.svg)![Ubiquiti UniFi](https://avepto.ch/_nuxt/unifi.DNiLZRSL.svg)![TP-Link Omada](https://avepto.ch/_nuxt/omada.ErQfaGf6.svg)

![Fortinet](https://avepto.ch/_nuxt/fortinet.BVt7gKvL.svg)![pfSense](https://avepto.ch/_nuxt/pfsense.xpCI-k1l.svg)![Ubiquiti UniFi](https://avepto.ch/_nuxt/unifi.DNiLZRSL.svg)![TP-Link Omada](https://avepto.ch/_nuxt/omada.ErQfaGf6.svg)

![Fortinet](https://avepto.ch/_nuxt/fortinet.BVt7gKvL.svg)![pfSense](https://avepto.ch/_nuxt/pfsense.xpCI-k1l.svg)![Ubiquiti UniFi](https://avepto.ch/_nuxt/unifi.DNiLZRSL.svg)![TP-Link Omada](https://avepto.ch/_nuxt/omada.ErQfaGf6.svg)

![Fortinet](https://avepto.ch/_nuxt/fortinet.BVt7gKvL.svg)![pfSense](https://avepto.ch/_nuxt/pfsense.xpCI-k1l.svg)![Ubiquiti UniFi](https://avepto.ch/_nuxt/unifi.DNiLZRSL.svg)![TP-Link Omada](https://avepto.ch/_nuxt/omada.ErQfaGf6.svg)

![Fortinet](https://avepto.ch/_nuxt/fortinet.BVt7gKvL.svg)![pfSense](https://avepto.ch/_nuxt/pfsense.xpCI-k1l.svg)![Ubiquiti UniFi](https://avepto.ch/_nuxt/unifi.DNiLZRSL.svg)![TP-Link Omada](https://avepto.ch/_nuxt/omada.ErQfaGf6.svg)

![Fortinet](https://avepto.ch/_nuxt/fortinet.BVt7gKvL.svg)![pfSense](https://avepto.ch/_nuxt/pfsense.xpCI-k1l.svg)![Ubiquiti UniFi](https://avepto.ch/_nuxt/unifi.DNiLZRSL.svg)![TP-Link Omada](https://avepto.ch/_nuxt/omada.ErQfaGf6.svg)

![Fortinet](https://avepto.ch/_nuxt/fortinet.BVt7gKvL.svg)![pfSense](https://avepto.ch/_nuxt/pfsense.xpCI-k1l.svg)![Ubiquiti UniFi](https://avepto.ch/_nuxt/unifi.DNiLZRSL.svg)![TP-Link Omada](https://avepto.ch/_nuxt/omada.ErQfaGf6.svg)

- Fortinet
- pfSense
- Ubiquiti UniFi
- TP-Link Omada

Installed or managed firewall

## A managed firewall means knowing what it protects, at all times.

Before

### Firewall installed once

Configuration Set at install, never revisited

Rules Accumulated without review

Firmware Updated occasionally

VPN Shared password, never rotated

Logs Collected, rarely reviewed

Documentation Partial, to be rebuilt

Monitoring Yet to be set up

Incidents Detected too late

After

### Actively managed firewall

Configuration Audited, simplified, justified

Rules Documented, reviewed regularly

Firmware Tracked, tested, scheduled

VPN WireGuard / IPsec, MFA, per-user access

Logs Centralised, reviewed, alerted

Documentation Kept up to date

Monitoring Active 24/7 on events

Incidents Detected, contained, explained

Three protection tiers

## Three protection tiers, from the router to a managed firewall.

For an SME of 5 to 80 people with a NAS, remote work and internal apps, the router shipped by your ISP isn’t enough. And a professional firewall, with no one to operate it, barely is either.

Criterion

Tier 1

ISP router

Router provided by your ISP

Tier 2

Pro firewall

Hardware installed, not operated

Tier 3

Managed firewall

Same hardware, operated

Application filtering

No

Yes (basic)

Yes, tuned for your business

VLAN segmentation

Limited

Yes

Designed, documented, verified

Secure VPN

PPTP / L2TP

Configurable IPsec

IPsec or WireGuard, MFA, per-user access

Isolated guest WiFi

Often no

Possible

Configured and tested

Firmware updates

Auto, opaque

Manual, forgotten

Scheduled and tested

Log review

Not planned

On you

Done at Avepto

Incident alerts

Not planned

To configure

Received and handled by Avepto

Rule documentation

Not provided

Rare

Delivered and kept up to date

Real SME cases from French-speaking Switzerland

## Five profiles. One method.

Trustee firm 12 staff

### Fiduciary office

Financial data, client access, remote work for staff. Strict segmentation, logging, per-user VPN.

central Geneva

Medical 8 staff

### Medical practice

Patient data, confidentiality requirements, controlled backups. Strict isolation of the guest network.

Vaud

Remote work 32 staff

### Distributed company

Staff in Switzerland, neighbouring France, sometimes travelling. MFA VPN, per-user access, instant revocation.

multi-site

Multi-site 55 staff

### Multi-site company

Two or three permanently connected offices. Encrypted site-to-site tunnels, unified security policy, central traffic monitoring.

GE and VD

NAS / server 40 staff

### SME with on-prem server

ERP, NAS and in-house apps hosted on site. Inbound filtering, controlled remote access, traffic monitoring.

Satigny

Your SME

### Your situation is unique.

Every SME has its own constraints. Let’s meet and talk about your network as it is, not as it should be.

Book a meeting

Anonymised typical day

## Every day your network is probed, tested, scanned. Just another day.

Port scans, passwords tried in bursts, addresses already flagged elsewhere. Your firewall forwards every event to a central analysis that cross-checks, decides and blocks within seconds.

Client perimeter log UTC+01

02:14 Port sweep across the public address, source isolated at once Reconnaissance

04:53 Passwords tried in bursts on a remote access, blocked at threshold Brute force

07:38 Address already flagged elsewhere on the network, denied before its first request Shared reputation

10:22 Unusual traffic toward an internal host, session refused by current policy Filtering

13:09 Connection spike from a single IP block, temporary rule pushed to the firewall Automatic action

Auto-blocked 1,240 Actions required 0

Frequently asked

## Your network, explained plainly.

A question that isn’t here? The audit answers it directly.

### Does the company’s network hardware need replacing to be secured?

Replacement only when justified

Not necessarily. Avepto replaces network equipment only if it is obsolete, no longer supported by the vendor, or can no longer meet your needs. In that case we say so explicitly, with the costs spelled out, and we steer you toward a solution we know well. The rest of the time, we make the most of what you have.

### Does the network takeover cause downtime for the SME?

Cutover scheduled outside business hours

As a rule, no. Significant changes are scheduled outside business hours, agreed with you, so your team isn’t interrupted. A planned cutover typically takes 15 to 30 minutes, and we tell you the exact window in advance.

### How does the VPN work for remote work in an SME?

Per-user VPN with multi-factor authentication

The virtual private network (VPN) gives per-user named access, protected and logged. When someone leaves the company, their remote access is revoked immediately, closing a door that’s often forgotten.

### Is the guest WiFi truly isolated from the company’s internal network?

Guest WiFi isolation via VLAN

Yes. The guest WiFi sits on a separate virtual local area network (VLAN), with no access to the internal network or the storage server (NAS), and strict rules on outbound traffic. Avepto re-checks this isolation periodically so a visitor or an unknown device cannot reach your data.

### What does network segmentation mean for an SME, concretely?

Segmentation into distinct zones

Network segmentation means separating offices, servers, printers, guest WiFi and connected objects (IoT) into distinct zones. If one workstation is compromised, the attack stays inside its zone and doesn’t automatically reach the rest of the network. It’s a simple, effective internal barrier.

Continue exploring

## Related services, and the reading that goes with them.

The services most often deployed alongside this one, and the field notes published by our specialists.

Related services

- [Antivirus & EDR Endpoint detection. Blocks and isolates.](https://avepto.ch/en/cybersecurity/antivirus)
- [Identity management MFA, SSO, access reviews.](https://avepto.ch/en/cybersecurity/identity)
- [VPN Managed remote access. Tunnels monitored.](https://avepto.ch/en/productivity/vpn)
- [Recovery plans A recovery plan and continuity. Off-site copy held in Switzerland.](https://avepto.ch/en/cybersecurity/disaster-recovery)

Next step

## Your network, monitored and managed by Avepto.

We meet, we walk through your network together, and you leave with useful recommendations. What happens next is up to you, no commitment.