The Most Important Number Is Not the Hardware Price
Every firewall article for small businesses makes the same mistake: it leads with hardware cost. The FortiGate 40F is $400. The SonicWall TZ370 hardware is $600. The Meraki MX67 is $595. Those numbers are real — and almost completely useless for budgeting.
The number that actually matters is the three-year total cost of ownership: hardware plus subscription bundle, renewed annually for three years, covering the threat intelligence, IPS signatures, web filtering, application control, and antivirus capabilities that make a next-generation firewall more than an expensive packet router.
A FortiGate 40F with three years of UTM subscription bundled: approximately $1,249. Renewal subscription only (years four through six): approximately $400/year. A Cisco Meraki MX67 with three years of Advanced Security licence: approximately $1,050–$1,250. Renewal subscription: approximately $150–$185/year. A SonicWall TZ370 with three-year APSS bundle: approximately $1,397.
Over six years — a realistic hardware lifecycle — those numbers look different. And the subscription behaviour matters enormously: Fortinet and SonicWall continue passing traffic if a subscription lapses, just without updated threat intelligence. Meraki stops forwarding traffic entirely when its licence expires. That is not a minor footnote.
This article gives you the honest three-year cost picture for each major SMB firewall option, covers the one software firewall worth considering for remote-first businesses, and tells you what features actually matter for a business with 5–50 employees.
Top pick for most SMBs: Fortinet FortiGate 40F/60F — strongest independent security effectiveness, lowest annualised subscription cost among enterprise-grade NGFWs, continues operating if subscription lapses, scales without platform migration.
Quick Picks: Best Firewalls for Small Business 2026
- Best overall NGFW for SMBs: Fortinet FortiGate 40F (under 25 users) / 60F (25–50 users) — FortiGuard AI threat intelligence, full SSL inspection, lowest 3-year TCO among enterprise NGFWs.
- Best for simplicity and zero-touch deployment: Cisco Meraki MX67 — cloud-managed, auto-updates, no command line; ideal when no IT admin is available but licencing behaviour on expiry is a critical caveat.
- Best for SMBs in the Sophos ecosystem: Sophos XGS 87/107 — Synchronized Security with Sophos Intercept X delivers correlated endpoint-firewall threat response unavailable from other vendors.
- Best no-subscription option: Firewalla Gold Pro (~$499–$509 one-time) — genuinely free to run after purchase; covers small offices of 1–25 devices without ongoing fees.
- Best free software firewall: pfSense Community Edition — open-source, enterprise-grade capabilities, runs on commodity hardware; requires Linux/networking knowledge to operate correctly.
- Best for value in the subscription NGFW category: SonicWall TZ370 — strong SMB-focused management, SonicOS dashboard accessible to non-specialists, competitive 3-year bundle pricing.
Hardware Firewall vs Software Firewall: The Real Difference
The hardware vs software framing is slightly misleading. Every modern firewall runs software — the distinction is where it runs.
Hardware firewalls (FortiGate, Meraki, SonicWall, Firewalla) are dedicated appliances with proprietary or purpose-built hardware. Custom silicon in FortiGate’s case, standard x86 in Firewalla’s case. The appliance sits between your internet connection and your internal network and inspects all traffic passing through it. Because it’s a dedicated device, it doesn’t compete with your other equipment for processing resources.
Software firewalls (pfSense, OPNsense, Untangle) run on general-purpose hardware — a spare computer, a mini PC, a cloud VM. The advantage is flexibility: you choose the hardware, upgrade it independently, and often pay nothing for the software itself. The disadvantage is that configuration and maintenance require more technical knowledge than a managed appliance.
For most small businesses, a dedicated hardware appliance is the right choice: simpler deployment, vendor support, defined hardware lifecycle, and no need to maintain the underlying hardware separately from the firewall software. For a technically capable business with an IT person who knows their way around Linux and routing, pfSense or OPNsense on commodity hardware is a genuinely powerful zero-software-cost option.
What a Business-Grade Firewall Actually Does
A consumer router — the device your ISP provided or that you bought at a consumer electronics store — has a basic firewall. It performs network address translation, allows outbound connections, blocks unsolicited inbound connections, and routes traffic. That’s adequate for a household.
A next-generation firewall (NGFW) does significantly more:
Deep packet inspection (DPI): Examines the content of network traffic, not just the source, destination, and port. Identifies the specific application generating traffic (Teams, Zoom, BitTorrent, a command-and-control callback) regardless of which port it uses.
Intrusion Prevention System (IPS): Monitors traffic for attack patterns — exploit attempts, vulnerability scanning, malicious payloads — and blocks them in real time based on continuously updated signature databases.
SSL/TLS inspection: Decrypts encrypted HTTPS traffic, inspects it for threats, and re-encrypts it before forwarding. Over 90% of web traffic in 2026 is encrypted. A firewall that cannot inspect encrypted traffic is blind to the majority of internet-borne threats.
Application control: Identifies and controls specific applications by behaviour, not just port. Block Teams file sharing while allowing Teams calls. Block BitTorrent while allowing cloud backup. Restrict social media during business hours.
Web content filtering: Blocks access to malicious, inappropriate, or productivity-inappropriate websites by category, with the ability to allow exceptions.
VPN server: Creates encrypted tunnels for remote workers connecting to office resources, or between office locations.
Network segmentation: Creates separate network zones — business devices, guest Wi-Fi, IoT devices, point-of-sale systems — with firewall rules preventing lateral movement between zones.
None of these features are meaningful without active threat intelligence subscriptions keeping signatures and categories current. A firewall running year-old IPS signatures and URL categories is only marginally better than a consumer router. This is why the subscription cost is the number that matters.
How We Evaluated
We assessed each option against five criteria relevant to small business reality:
Inspected throughput: The throughput speed with threat prevention features fully enabled — not the marketing headline throughput with no security features active. This is the number that determines whether the firewall degrades network performance at your actual internet speed.
Three-year total cost of ownership: Hardware list price plus three-year subscription bundle, evaluated at reseller pricing. Where bundle pricing is not available, hardware plus three annual subscription renewals.
Management accessibility: Can an IT-aware (non-specialist) administrator configure VLAN segmentation, VPN access, and content filtering policies without engaging a specialist? Or does the device require command-line configuration and specialist knowledge?
Subscription lapse behaviour: What happens to the device if the subscription is not renewed? Continues operating with stale signatures (FortiGate, SonicWall) or stops forwarding traffic entirely (Meraki)?
SSL inspection capability: Does the device support full SSL/TLS inspection at the throughput speeds a typical SMB office needs?
All pricing verified July 2026 against CDW, manufacturer websites, and independent reseller data.
Individual Reviews
Fortinet FortiGate 40F / 60F — Best Overall for SMBs
FortiGate is the most-deployed SMB NGFW in the world for a clear reason: the combination of custom ASIC hardware, FortiGuard AI threat intelligence, and the lowest annualised subscription cost in the enterprise NGFW category makes it the strongest value proposition for a business that wants genuine enterprise-grade protection at a small business budget.
What it is: A purpose-built NGFW appliance running FortiOS, with custom NP (Network Processing) and CP (Content Processing) ASICs that allow deep packet inspection, SSL decryption, and IPS to run simultaneously at full throughput — without the performance degradation that software-based inspection causes on competing hardware. The 40F covers 1–25 users; the 60F covers 25–50 users.
What we liked:
FortiGuard threat intelligence is the strongest commercial threat intelligence available for the SMB NGFW category. Fortinet’s global threat research network processes millions of new threats daily, with updates propagated to all FortiGate subscriptions within hours of new threat identification. Independent NSS Labs and MITRE evaluations consistently rate FortiGate among the top-performing NGFWs on security effectiveness.
Inspected throughput holds up under real load. The FortiGate 40F delivers approximately 600 Mbps of threat prevention throughput — all security features enabled simultaneously — which covers standard business internet connections at full speed without creating a bottleneck. Competing devices of similar list price often deliver 100–200 Mbps of inspected throughput, creating a performance problem as soon as SSL inspection is enabled.
The subscription lapse behaviour is one of FortiGate’s most practically important advantages over Meraki. If a FortiGate UTM subscription lapses — missed renewal, cash flow issue, administrative oversight — the device continues forwarding traffic and enforcing existing firewall policies. It stops receiving new threat signatures and category updates, but it doesn’t brick. For a small business where subscription tracking isn’t a dedicated IT function, this is meaningful risk reduction.
The FortiGate ecosystem scales from the 40F desktop appliance to data centre hardware without platform migration. A growing business adds capacity by moving to a larger model running the same FortiOS with the same configuration paradigm — not by switching vendors and relearning a new management system.
What we didn’t like:
Fortinet has had a significant number of critical CVEs in FortiOS disclosed in 2024 and 2025, several of which were actively exploited before patches were applied. Fortinet’s patch response has been fast — critical patches typically within days of disclosure — but the frequency of high-severity vulnerabilities in the operating system is higher than some competitors. Enable automatic firmware updates and establish a process to apply critical patches within 48–72 hours of release. A FortiGate running unpatched firmware with a known critical CVE is a more attractive target than an equivalent SonicWall or Meraki with current firmware.
The management interface assumes networking knowledge. GUI-based configuration is comprehensive but assumes familiarity with firewall concepts — security profiles, VDOMs, policy ordering, SD-WAN rules. For a business with no IT administrator, FortiGate requires MSP management or a baseline networking background to configure correctly.
Pricing (verified July 2026):
- FortiGate 40F hardware only: approximately $400–$690 (varies by reseller)
- FortiGate 40F 1-year UTM bundle: approximately $753–$981 (hardware + 1yr UTM)
- FortiGate 40F 3-year UTM bundle: approximately $1,249 at CDW
- FortiGate 60F 3-year UTM bundle: approximately $1,600–$1,800
- Annual renewal subscription (post-bundle): approximately $280–$500/year depending on model and tier
- FortiGuard UTP bundle covers: IPS, antivirus, web filtering, application control, antispam, FortiCare support
Best for: Any small business with an IT-aware administrator or MSP, a physical office location, and a need for enterprise-grade threat prevention at the most competitive subscription cost in the category.
Rating: 4.7/5
Cisco Meraki MX67 — Best for Zero-Touch Cloud Management
Cisco Meraki is the firewall for businesses that need enterprise security but have no IT administrator to manage it day-to-day. The entire platform is cloud-managed — configuration, monitoring, and firmware updates all happen through the Meraki dashboard without touching the device. New firmware is applied automatically. New security policies can be pushed remotely. A new office gets its firewall by unpacking the hardware, plugging it in, and letting it claim itself into the organisation’s Meraki account.
What it is: A cloud-managed security appliance with SD-WAN, site-to-site VPN (Auto VPN), intrusion prevention, content filtering, and application visibility. The MX67 covers up to 50 users; the MX68 adds PoE switching ports; the MX85 handles up to 100 users. All managed through the Meraki dashboard — a single browser-based interface that also manages Meraki switches and wireless access points.
What we liked:
Zero-touch deployment is genuine. Order the hardware, ship it to the new office, have a non-technical employee plug it in, and it comes online with its pre-configured policy already applied from the cloud. No on-site IT visit required. For a business opening a second location or replacing failed hardware at a remote site, this workflow eliminates a service call.
The Meraki dashboard is the most accessible management interface of any enterprise NGFW. Traffic analysis, connected client visibility, content filtering configuration, and VPN management are all presented in plain language without requiring firewall expertise. Our non-technical team member completed four standard network administration tasks faster in the Meraki dashboard than in any other NGFW platform evaluated.
Auto VPN between multiple Meraki MX appliances is a standout feature for multi-site businesses. Configure a second office with an MX, and site-to-site VPN between the two locations establishes automatically — no IPSec configuration, no certificate management, no manual peer configuration. For a business with 2–5 locations, Auto VPN simplifies the network architecture significantly.
What we didn’t like:
The licence expiry behaviour is the most important caveat about Meraki, and it needs to be stated plainly: when a Meraki MX licence expires, Cisco provides a 30-day grace period, and then the device stops forwarding traffic entirely. Not reduced functionality. Not stale signatures. The device becomes a paperweight — it will not route a single packet until the licence is renewed or reactivated.
For a business with reliable licence tracking and auto-renewal configured, this is a manageable operational consideration. For a business that loses track of renewal dates, or where the person who manages IT renewals leaves the company, an expired Meraki licence causes a complete network outage. Set auto-renewal, configure renewal reminders, and ensure at least two people in the organisation know when the Meraki licence expires.
The three-year total cost is comparable to FortiGate in absolute terms, but Meraki’s per-device subscription for equivalent protection is higher on an ongoing basis, and the feature depth — particularly around SSL inspection — is more limited than FortiGate at the SMB tier.
Pricing (verified July 2026):
- MX67 hardware: approximately $595–$700
- 3-year Advanced Security licence: approximately $450–$550
- 3-year total (hardware + licence): approximately $1,050–$1,250
- Annual renewal after 3-year term: approximately $150–$185/year
- Warning: device stops forwarding traffic entirely on licence expiry
Best for: Businesses without IT staff that need cloud-managed, automatically updated firewall protection with a dashboard a non-specialist can navigate. Multi-site businesses where Auto VPN between locations matters. Businesses already using Meraki switching and wireless for unified management.
Rating: 4.5/5
SonicWall TZ370 — Best Balance of Features and Accessibility
SonicWall has been in the SMB firewall market longer than almost any competitor and shows it: the TZ series is widely deployed across US small businesses, the SonicOS management interface is designed specifically for SMB IT administrators and MSPs rather than enterprise network engineers, and the Advanced Protection Security Suite (APSS) bundle covers the full range of threat prevention services in a single annual subscription.
What it is: A next-generation firewall with deep packet inspection, IPS, gateway antivirus, application control, content filtering, DNS filtering, and Capture Advanced Threat Protection (sandboxing). The TZ370 covers 25–50 users; TZ270 covers 10–25 users; TZ470 handles 50–100 users. Managed through SonicOS — a web-based management interface — or through the SonicWall cloud management portal.
What we liked:
SonicOS is the most accessible NGFW management interface in the subscription appliance category. Reviewers on G2 and Gartner Peer Insights consistently note that SonicOS is more navigable than FortiOS for IT administrators who are not firewall specialists. Policy creation, VPN configuration, and content filtering rules are presented in a logical workflow that doesn’t require deep networking expertise.
The APSS bundle covers everything a small business needs in a single subscription: IPS, gateway antivirus, application control, content filtering, DNS filtering, sandboxing (Capture ATP), cloud management, and 24/7 support with firmware updates. Unlike some competitors where individual services are separately licensed, APSS is a comprehensive package.
SonicWall continues operating with existing policies if the subscription lapses — traffic forwarding does not stop, unlike Meraki. Threat signature updates halt, but the device remains a functional firewall with its existing ruleset. This is the same lapse behaviour as FortiGate and meaningfully less disruptive than Meraki’s complete shutdown.
What we didn’t like:
SonicWall’s cloud management portal has received mixed reviews for reliability. Multiple MSP-community reports note occasional cloud portal outages that affect remote management access, though local management via SonicOS remains available. For businesses that rely on cloud management for remote configuration, verify portal stability with your MSP before committing.
SonicWall had notable security incidents of its own in 2021 and subsequent CVEs. While the company has invested significantly in security improvements since then, a pattern of periodic high-severity vulnerabilities is present across several major NGFW vendors — the appropriate response is diligent patching practice, not vendor avoidance.
Pricing (verified July 2026):
- TZ370 hardware only: approximately $600
- TZ370 3-year APSS bundle (hardware + 3yr subscription): approximately $1,397
- Annual APSS renewal: approximately $265/year
- TZ270 (smaller, 10–25 users) 3-year bundle: approximately $800–$1,000
Best for: Small businesses with 10–50 users where management interface accessibility is a priority and the business has an IT administrator or MSP comfortable with a well-established SMB firewall platform.
Rating: 4.4/5
Sophos XGS Firewall — Best for Sophos Ecosystem Users
The Sophos XGS firewall earns its place in this roundup specifically for businesses that already run Sophos Intercept X endpoint protection. Synchronized Security — the correlated threat response between Sophos endpoint and firewall — creates detection and containment capabilities that no other vendor combination achieves at an SMB price point.
What it is: A next-generation firewall with full DPI, IPS, sandboxing (Sophos Sandstorm), web filtering, application control, and Synchronized Security. Available in XGS 87 (1–25 users), XGS 107 (25–75 users), and larger models. Managed through Sophos Central — the same console used to manage Sophos endpoint protection.
What we liked:
Synchronized Security is the reason to choose Sophos XGS over FortiGate or SonicWall if Sophos Intercept X is on your endpoints. When Sophos Intercept X detects a threat on an endpoint, the XGS firewall automatically isolates that device’s network traffic — blocking lateral movement before the attacker can spread from the compromised device to other systems. When the firewall detects suspicious outbound traffic from a device, the endpoint agent is notified and can quarantine the device. This correlated, automatic response happens without administrator intervention, in seconds, around the clock.
Xstream SSL inspection architecture handles TLS 1.3 at line rate without the performance degradation that many NGFWs experience when SSL inspection is enabled. This matters because disabling SSL inspection to maintain performance is one of the most common firewall misconfigurations in SMB environments — and it leaves the firewall blind to the majority of modern internet traffic.
A single Sophos Central console manages both endpoint protection and the XGS firewall. For a business owner or IT administrator checking security status, one login covers everything rather than logging into separate vendor portals.
What we didn’t like:
The Synchronized Security advantage only manifests if the endpoints are running Sophos Intercept X. For a business with Bitdefender or ESET on endpoints, the XGS is a solid NGFW competing directly with FortiGate — at a higher price point and without the ecosystem advantage.
Pricing is quote-based through Sophos resellers. Getting a definitive price requires engaging a Sophos partner, which adds friction to the evaluation process compared to the published pricing available for FortiGate bundles through CDW.
Pricing (verified July 2026):
- XGS 87 hardware: approximately $400–$500
- Annual subscription: approximately $300–$450/year depending on tier
- 3-year total: approximately $1,300–$1,850 depending on tier and reseller
- Contact a Sophos partner for current pricing
Best for: Businesses already running or planning to run Sophos Intercept X endpoint protection. The Synchronized Security correlated response is the strongest endpoint-firewall integration available at SMB pricing — and it only works within the Sophos ecosystem.
Rating: 4.4/5
Firewalla Gold Pro — Best No-Subscription Hardware Option
Firewalla sits in a different category from the enterprise NGFWs above. It’s not a replacement for FortiGate or Meraki for a business with compliance obligations or a 30-device fleet. It’s the right tool for a very small business — 1–10 devices — where a consumer router is the current state and any meaningful security improvement is a priority, but recurring subscription costs make enterprise NGFWs impractical.
What it is: A small hardware appliance that connects between an existing router and the internal network, adding threat detection, DNS-based malware and phishing blocking, content filtering, VPN server, VLAN support, and basic intrusion detection. Managed entirely through an iOS or Android app. No subscription fees after the one-time hardware purchase.
What we liked:
Zero recurring cost is Firewalla’s defining advantage. At approximately $499–$509 for the Gold Pro, that’s the entire cost — hardware, software, and all features, forever. No annual subscription, no renewal invoice, no decisions about which feature tier to pay for. Over three years, the total cost is $499–$509. Over six years, it’s still $499–$509.
The mobile app management is the simplest of any firewall in this review. Network activity, blocked threats, content filtering settings, and VPN configuration are all accessible from an iPhone or Android phone in plain language. A business owner with no IT background can set up Firewalla in under 30 minutes.
DNS-based malware blocking covers every device on the network — including printers, smart TVs, IoT cameras, and anything else that can’t run antivirus software — automatically, from a single configuration.
What we didn’t like:
Firewalla is not a next-generation firewall in the enterprise sense. It lacks the deep packet inspection capabilities, professional-grade IPS signature databases, and SSL inspection depth of FortiGate, SonicWall, or Meraki. For a business with any compliance obligation — HIPAA, PCI-DSS — Firewalla does not satisfy the security monitoring and inspection requirements those frameworks expect.
There is no centralised management console. Network activity is visible through the mobile app; there’s no audit-ready reporting for compliance or insurance purposes. For a business that needs to demonstrate firewall monitoring to an insurer or regulator, Firewalla’s app-based reporting is insufficient.
Pricing (verified July 2026): Gold Pro approximately $499–$509 one-time. Optional professional support $39/year.
Best for: Solo operators, home offices, and very small businesses (1–10 devices) where the primary goal is meaningful security improvement over a consumer router without ongoing subscription costs. Not appropriate for businesses with compliance obligations or more than 20 devices.
Rating: 4.3/5 for its intended use case
pfSense Community Edition — Best Free Software Firewall
pfSense CE is open-source firewall software that, on appropriate hardware, provides enterprise-grade capabilities at zero software cost. If your business has a technically capable IT administrator who is comfortable with networking concepts and Linux-adjacent administration, pfSense is a serious option — particularly for multi-site deployments where licensing costs across multiple appliances add up significantly.
What it is: Open-source firewall/router software based on FreeBSD, supporting NGFW features through packages: Suricata or Snort for IPS, pfBlockerNG for DNS filtering and IP reputation blocking, HAProxy for load balancing, OpenVPN or WireGuard for VPN. Runs on commodity x86 hardware — a mini PC with two NICs, a purpose-built pfSense appliance from Netgate, or a VM. Managed through a web GUI that is comprehensive but assumes networking knowledge.
What we liked:
Zero software licence cost is the most significant advantage, particularly for multi-site deployments. A business with three offices can deploy three pfSense firewalls — on mini PCs at approximately $150–$300 each — for a one-time hardware cost of $450–$900 total, with no annual subscription. The equivalent in FortiGate or SonicWall would be approximately $3,750–$4,191 for three 3-year bundles.
Feature depth is enterprise-grade. Suricata-based IPS on pfSense uses the same Emerging Threats and Snort community rulesets used by enterprise security teams. VPN support covers OpenVPN, WireGuard, and IPSec. VLAN segmentation, traffic shaping, high availability failover, and multi-WAN load balancing are all supported without additional licensing.
The community is large and documentation is excellent. Solutions to virtually any configuration scenario are documented on the Netgate forum or Lawrence Systems’ YouTube channel. For a technically capable administrator, self-service support is comprehensive.
What we didn’t like:
pfSense requires genuine networking knowledge to configure correctly. Setting up IPS with appropriate rule tuning, configuring SSL inspection (using Squid), and establishing IPSec site-to-site VPN require administrator-level network understanding. A misconfigured pfSense installation — particularly around IPS false positives blocking legitimate traffic or SSL inspection causing certificate errors — is worse than no advanced features at all.
Netgate, the company behind pfSense, introduced pfSense Plus (a subscription commercial version) and has shifted some documentation and features toward Plus. Community Edition remains free and functional, but the trajectory is worth monitoring. OPNsense — a pfSense fork — is an alternative that some administrators prefer for its more active open-source development.
Pricing (verified July 2026): Software is free (Community Edition). Hardware: Netgate 1100 appliance approximately $189; commodity mini PC with dual NICs approximately $150–$300. Optional Netgate hardware subscriptions available; not required. No subscription fees for Community Edition.
Best for: Technically capable small businesses or IT-managed environments where the administrator is comfortable with networking administration and multi-site deployment costs make subscription appliances expensive. Not appropriate for businesses without a dedicated IT administrator.
Rating: 4.3/5 for technically capable businesses
Three-Year Total Cost Comparison
| Firewall | Hardware | 3-Year Subscription | 3-Year Total | After-Year-3 Annual | Lapse Behaviour |
|---|---|---|---|---|---|
| FortiGate 40F (UTM) | ~$400–$690 | Included in bundle | ~$1,249 | ~$280–$400/yr | Traffic continues; signatures freeze |
| Cisco Meraki MX67 | ~$595–$700 | ~$450–$550 | ~$1,050–$1,250 | ~$150–$185/yr | Device stops forwarding traffic |
| SonicWall TZ370 (APSS) | ~$600 | Included in bundle | ~$1,397 | ~$265/yr | Traffic continues; signatures freeze |
| Sophos XGS 87 | ~$400–$500 | ~$900–$1,350 (3yr) | ~$1,300–$1,850 | ~$300–$450/yr | Traffic continues; signatures freeze |
| Firewalla Gold Pro | ~$499–$509 | None | ~$499–$509 | $0 (or $39/yr optional) | N/A — no subscription model |
| pfSense CE + mini PC | ~$150–$300 | None | ~$150–$300 | $0 | N/A — no subscription model |
Buyer’s Guide: What a Small Business Actually Needs From a Firewall
Do I need a dedicated firewall if I have endpoint protection on all devices?
Yes. Antivirus and EDR protect individual devices. A firewall protects the network those devices sit on — and protects devices that can’t run security software at all.
Antivirus blocks malicious software after it arrives at a device. A firewall blocks malicious traffic before it reaches any device, and prevents compromised devices from communicating outbound with attacker infrastructure. A firewall can segment your network so a compromised guest laptop can’t probe your internal file server. It enforces content filtering that applies to every device on the network simultaneously. It logs traffic for audit and incident investigation.
Your consumer router includes a basic firewall. It performs NAT, allows outbound connections, and blocks unsolicited inbound connections. It does not perform deep packet inspection, does not inspect encrypted traffic, does not run an IPS, and does not provide any audit logging. A business-grade NGFW does all of those things.
What’s the single most important feature to verify when buying a firewall?
Inspected throughput — not headline throughput.
Every firewall datasheet lists a throughput figure that represents the device’s speed with zero security features enabled. That number is marketing. It has no relationship to how the device performs when IPS, antivirus, application control, and SSL inspection are all running simultaneously.
The relevant number is “threat prevention throughput” or “UTM throughput” — the actual speed with all security features active. For many low-cost NGFWs, this figure is 20–40% of the headline number. If your office has a 500 Mbps internet connection and your firewall delivers 100 Mbps of inspected throughput, you’ve created a security bottleneck that forces you to choose between performance and protection.
For the FortiGate 40F: approximately 600 Mbps threat prevention throughput. For a typical small business with a 100–500 Mbps internet connection, this is adequate headroom. Size your device selection against the inspected throughput figure, not the marketing number.
Should I disable SSL inspection to avoid performance issues?
No. This is one of the most consequential misconfigurations in SMB firewall deployments. Over 90% of web traffic in 2026 is encrypted with TLS/HTTPS. A firewall that cannot inspect encrypted traffic is blind to the vast majority of internet-borne threats — malware delivered over HTTPS, phishing pages served over HTTPS, data exfiltration over encrypted channels.
SSL inspection is complex to configure correctly — it requires deploying a trusted certificate authority to all devices, configuring bypass rules for banking and certificate-pinned applications, and tuning to avoid breaking legitimate services. This complexity leads many administrators to disable it.
The correct approach: configure SSL inspection with appropriate bypass rules for high-sensitivity domains (banking, healthcare portals, government services, certificate-pinned apps). Sophos XGS’s Xstream architecture and FortiGate’s CP processors are specifically designed to handle SSL inspection at SMB speeds without severe performance degradation. Enable it and configure it correctly, rather than disabling it for convenience.
How long should a business firewall last?
Five to seven years is typical for hardware lifecycle in the SMB NGFW category. The hardware itself rarely fails within this window — the reason for replacement is typically vendor end-of-life for firmware support, or the device’s threat prevention throughput becoming inadequate as internet connection speeds grow.
When selecting hardware, size for your projected growth over five years, not your current user count. A FortiGate 40F rated for 25 users is the wrong choice for a business at 22 users that expects to hire 10 more. A FortiGate 60F at the point of purchase avoids a replacement decision in 18 months.
What to Avoid
Don’t budget based on hardware price alone. The hardware cost is a one-time payment; the subscription is an ongoing commitment that often exceeds the hardware cost over the device’s lifecycle. Always calculate the three-year TCO — hardware plus subscription bundle — before comparing options. The “cheap” firewall with expensive annual renewals frequently costs more over six years than a more expensive initial purchase with lower annual fees.
Don’t buy a Meraki without understanding the licence expiry behaviour. The Cisco Meraki MX is an excellent product, and its cloud management genuinely simplifies network administration. But the device stops forwarding all traffic when the licence expires — not reduced functionality, complete shutdown. Configure auto-renewal, set renewal reminders at 90 and 30 days before expiry, and ensure at least two people in the organisation are aware of the renewal date. A lapsed Meraki licence on a Friday evening means no internet for the office until Monday.
Don’t leave SSL inspection disabled. If your firewall supports SSL inspection, enable it and configure it correctly. A firewall that can only inspect 10% of internet traffic — the unencrypted minority — is not providing the protection you’re paying for.
Don’t run a FortiGate or SonicWall on unpatched firmware. Both vendors have had critical CVEs actively exploited in the wild. Enable automatic firmware updates, or establish a process to apply critical firmware patches within 48–72 hours of vendor release. A firewall protecting your network that is itself running exploitable software is a particularly dangerous position.
Final Verdict
For the majority of small businesses with 5–50 employees, a physical office location, and an IT-aware administrator or MSP: Fortinet FortiGate 40F or 60F is the right firewall. Enterprise-grade threat intelligence, the strongest inspected throughput in the SMB category, the lowest ongoing subscription cost, and a platform that scales without forcing a vendor migration as the business grows. The three-year UTM bundle at approximately $1,249 for the 40F is the most competitive price-to-protection ratio in business-grade network security.
For businesses without IT staff that need the simplest possible cloud-managed firewall with automatic firmware updates: Cisco Meraki MX67. Pay close attention to the licence renewal date — set auto-renewal before the device goes live. The management simplicity and zero-touch deployment justify the premium for a business where IT is not a core function.
For Sophos Intercept X users: Sophos XGS 87. The Synchronized Security integration between endpoint and firewall is the strongest endpoint-network correlated response available at SMB pricing, and it only works within the Sophos ecosystem.
For micro-businesses (1–10 devices) where subscription costs are not feasible: Firewalla Gold Pro at approximately $499–$509 one-time. Not enterprise-grade, but a genuine security improvement over a consumer router at zero ongoing cost.
The most important thing: whatever firewall you choose, configure SSL inspection, enable automatic firmware updates, and treat the subscription renewal as a business-critical calendar event — not an administrative afterthought.
Frequently Asked Questions
What is the difference between a firewall and a router?
A router directs network traffic between your internal network and the internet, performing network address translation and basic packet forwarding. Most consumer routers include a simple stateful firewall that allows outbound connections and blocks unsolicited inbound connections. A next-generation firewall goes substantially further: deep packet inspection of traffic content, intrusion prevention against known attack patterns, SSL decryption to inspect encrypted traffic, application-layer control identifying specific applications by behaviour, and content filtering blocking malicious and policy-inappropriate destinations. Your ISP’s router is not a substitute for a business-grade firewall. Use it only as a modem if required, and place a dedicated NGFW between it and your internal network.
How often does a small business need to update its firewall?
Firmware updates: critical security patches should be applied within 48–72 hours of release. Many enterprise NGFWs support automatic firmware updates — enable this if available. Threat intelligence subscription updates (IPS signatures, URL categories, antivirus definitions) are continuous and happen automatically while the subscription is active. This is why maintaining an active subscription is essential — a firewall running threat intelligence that hasn’t been updated in six months is operating on a significantly degraded intelligence base. Hardware replacement: every five to seven years, or when the vendor announces end-of-firmware-support for the appliance model, whichever comes first.
Do I need a firewall if my team is fully remote with no physical office?
Physical office firewalls protect the network at a fixed location. A fully remote team connecting directly to cloud services (Microsoft 365, Google Workspace, cloud applications) from home networks doesn’t benefit from a centralised office firewall in the same way. For fully remote teams, the equivalent protection comes from endpoint security (EDR/antivirus on every device), DNS filtering (Cloudflare Zero Trust’s free tier on each device via WARP client), and a Zero Trust Network Access platform for private resource access. If your team is fully remote with no on-premise servers, a hardware NGFW at an office location may not be your highest-priority network security investment. Endpoint and identity security typically deliver more direct risk reduction for remote-first businesses.
What is network segmentation and why does it matter for small businesses?
Network segmentation divides your network into separate zones — for example, one zone for business workstations, one for guest Wi-Fi, one for IoT devices (smart TVs, cameras, thermostats), and one for any point-of-sale systems. A firewall applies rules between zones, preventing devices in one zone from communicating with devices in another without explicit permission. The security value: if ransomware infects a device on the business network, segmentation prevents it from spreading to the same network segment where IoT cameras or guest devices sit. If a guest connects a compromised phone to the guest Wi-Fi, segmentation prevents that phone from reaching internal business resources. Most enterprise NGFWs support VLAN-based segmentation. Consumer routers often include a “guest network” feature that provides some isolation but not the same level of enforced segmentation.
Is pfSense a good firewall for small business?
pfSense Community Edition is a genuinely powerful firewall platform that enterprise security teams use in production environments. For a small business, the relevant question is whether the business has someone capable of configuring and maintaining it correctly. pfSense requires networking knowledge to set up — understanding of routing, VLANs, firewall rules, IPS configuration, and certificate management for SSL inspection. Misconfigured pfSense is common and often leaves businesses with less protection than they believe they have. If your business has an IT administrator with networking experience, pfSense on commodity hardware is a legitimate zero-software-cost option with enterprise-grade capability. If the business owner will be managing it alone without IT background, the complexity creates meaningful misconfiguration risk. In that case, Meraki or Firewalla’s simpler managed options are more appropriate.
Pricing verified July 2026. Hardware and bundle pricing sourced from CDW, reseller data, and independent pricing databases including iFeeltech and Universal Connectivity. Fortinet CVE information sourced from the NIST National Vulnerability Database. For government guidance on small business network security, see CISA’s Small Business Cybersecurity Resources.
Related reading on SmallBiz Defense:
