Skip to content
Networks & firewalls

Business firewall in Morocco: the buying guide

Business firewall in Morocco: why replace the ISP router, UTM and NGFW features, sizing, Fortinet or WatchGuard, licences and installation steps.

By the ALLSAFE SOLUTIONS engineering team30 September 20267 min read
Secured server room

A business firewall is the appliance that sits between your network and the internet to decide what gets through, inspect the content of traffic and block threats. For an SMB in Morocco, it takes over the protection role from the ISP router: web filtering, intrusion prevention, stream antivirus, and secure VPN for remote staff and branch offices. A good purchase comes down to three decisions: a model sized on its throughput with protections enabled, a security licence that stays active, and an integrator who installs it and looks after it over time. Here is how we guide that choice as a Fortinet and WatchGuard partner.

Why a real firewall rather than the ISP router

The router supplied with your fibre line handles routing and address translation. It blocks unsolicited inbound connections, which feels like security. But it does not look at what allowed traffic contains: a workstation downloading a booby-trapped file or visiting a phishing site goes through unchecked.

A business firewall adds what the router lacks:

  • Content inspection, including encrypted traffic, where most threats now hide.
  • Web and DNS filtering: blocking malicious sites, forbidden categories and newly created domains.
  • Intrusion prevention: detecting attempts to exploit known vulnerabilities.
  • Robust VPN for remote workers and branches, with multi-factor authentication.
  • Segmentation: workstations, servers, cameras, telephony and guest WiFi on separate networks.
  • Usable logs to understand an incident and meet the requirements of an insurer or a major customer.

The ISP router stays in place, but as a simple modem in front of the firewall, which becomes the single point of control.

UTM, NGFW: what the acronyms mean

Vendors talk about UTM (Unified Threat Management) and NGFW (Next-Generation Firewall). For an SMB, the distinction has become mostly marketing: FortiGate and Firebox appliances combine both approaches in a single box.

Feature What it does Why it matters
Application firewall Recognises applications, not just ports Allow Microsoft 365, block an unapproved remote-access tool
Intrusion prevention (IPS) Compares traffic with attack signatures Stops exploitation of known flaws
Stream antivirus and sandbox Scans files in transit, isolates suspicious ones Catches malicious attachments before they reach the PC
Web and DNS filtering Rates sites and domains by reputation Cuts off phishing and malicious sites
SSL inspection Opens encrypted traffic to analyse it Without it, the other protections are blind
IPsec VPN and remote access Connects branches and remote staff Secure access to internal resources
SD-WAN Balances traffic across several links Continuity when a fibre line goes down

All of these features depend on an active subscription: signature and reputation updates are what make them effective.

Sizing criteria

The headline figure on the datasheet is raw firewall throughput, measured without inspection. It is useless for choosing. The only number that matters is throughput with protections enabled, called “Threat Protection” at Fortinet and “UTM” at WatchGuard.

Then five criteria move you up or down a model:

  1. Number of users, with headroom for growth and remote staff, each of whom uses a VPN tunnel.
  2. The sum of your internet links, if you add a second fibre line or 4G backup. The fibre choice comes first, as we explain in business fibre in Morocco.
  3. Internal traffic between segmented networks: backups, file server access, video surveillance.
  4. Ports required: carrier links, switches, servers, link to a second appliance.
  5. High availability: a pair of identical appliances if a firewall outage would stop the business.

Our detailed sizing grids are in FortiGate for SMBs: which model to choose and our WatchGuard Firebox guide for SMBs.

The brands we deploy

We install two vendors and choose based on your context, not habit.

  • Fortinet FortiGate: wide range, benchmark built-in SD-WAN, full ecosystem with switches and WiFi access points managed from the firewall. The natural choice for multiple sites, an industrial network or an IT team that wants fine-grained control.
  • WatchGuard Firebox: readable WatchGuard Cloud console, AuthPoint multi-factor authentication extended to Windows and Microsoft 365. The natural choice for a single-site SMB without a network administrator.

On pure security, both are equivalent for an SMB. We compare them criterion by criterion in FortiGate or WatchGuard: which firewall to choose.

Licences and support: what to buy

A firewall is bought in two parts: the appliance and the subscriptions. At Fortinet, FortiCare covers vendor support, hardware replacement and access to system updates, while the UTP or Enterprise Protection bundles provide the security services. At WatchGuard, the Basic Security Suite or Total Security Suite play that role.

Three simple rules:

  • Never buy the appliance with support only: it would route traffic without really filtering it.
  • Compare quotes over the same term and the same licence level.
  • Record the expiry date on delivery and have it tracked. We explain what happens at expiry in FortiGate licence renewal and FortiCare.

The integrator’s role

In Morocco, vendors sell through distributors and partners. Going through a certified integrator guarantees hardware from the official channel, which can be registered and is covered by vendor support, and an installation done to the manufacturer’s recommendations. An appliance bought outside the channel can cause problems when activating or renewing the licence.

The integrator’s job does not end at delivery: they size, configure, document and then maintain the appliance. That follow-up is what separates a firewall that protects from a firewall that is merely installed.

Installation steps

  1. Audit: inventory of sites, links, users, flows and the current configuration.
  2. Design: addressing plan, segmentation, filtering rules, VPN, SD-WAN where needed.
  3. Preparation: appliance configured in the workshop, firmware updated, licences registered.
  4. Cutover in an agreed window, with a rollback ready if a service stops responding.
  5. Hardening: administration closed to the internet, multi-factor authentication, SSL inspection, as in our 10 security settings after installing a FortiGate.
  6. Acceptance and documentation: per-service tests, network diagram, configuration backup.

Ongoing management

A firewall degrades if nobody looks after it: rules added as a quick fix and never removed, firmware falling behind, a licence expiring unnoticed. Day-to-day operation covers firmware updates after validation, regular rule reviews, reading logs and alerts, configuration backups and tracking licence expiry dates.

The most common mistakes

  1. Keeping the ISP router as the only protection “because it works”.
  2. Choosing a model on raw firewall throughput, then disabling inspection because everything slows down.
  3. Buying the appliance without a security licence, or letting it lapse.
  4. Exposing the administration interface to the internet, protected by a password alone.
  5. A VPN without multi-factor authentication.
  6. No segmentation: cameras, guests and servers on the same network.
  7. An appliance bought outside the official channel that cannot be registered.

Checklist before buying

  • Number of users, remote workers and sites, with growth headroom.
  • Throughput with protections enabled compared with the sum of internet links.
  • Internal traffic between segmented networks accounted for.
  • Ports and high availability defined.
  • Vendor chosen according to who will administer the appliance.
  • Security licence and support included, over the same term in every quote.
  • Hardware supplied by a certified partner and registered in your company’s name.
  • Cutover plan with rollback, and maintenance planned after go-live.

How we do it

We start with a free initial audit: a review of your current network, links, flows and remote-work needs. We then propose the right vendor, model and licence, with a hardware and licence quote over the same term. We prepare, install and harden the firewall, then monitor it 24/7; a critical incident is handled in under 15 minutes. This work is part of our cybersecurity offering, alongside our network infrastructure services. You can see comparable, anonymised projects in our case studies.

Looking for a business firewall in Morocco? Contact us for your free initial audit: we reply within 24 business hours.

Frequently asked questions

Isn’t the ISP router enough to protect an SMB?

No. It translates addresses and blocks unsolicited inbound connections, but it does not inspect traffic, filter browsing, detect intrusions or handle VPN properly. It remains useful as a plain modem in front of a real firewall.

Which firewall brand should I choose in Morocco?

We deploy Fortinet (FortiGate) and WatchGuard (Firebox), two vendors present in Morocco with a partner network. FortiGate suits multi-site networks and advanced needs; WatchGuard suits SMBs that want simple administration and built-in multi-factor authentication.

Do I need to pay for a licence on top of the appliance?

Yes. Vendor support and security services (antivirus, web filtering, intrusion prevention) are subscriptions. Without them, the appliance still routes traffic but no longer receives protection updates. Always compare quotes with hardware and licences included, over the same term.

How long does it take to install a business firewall?

It depends on the number of sites, the rules to migrate and the networks to segment. We prepare the configuration in advance and cut over in a window agreed with you, with a rollback ready, to keep downtime to a minimum.

About the editorial team

ALLSAFE SOLUTIONS

Network, security and cloud engineers

Written by the engineering team at ALLSAFE SOLUTIONS, a managed IT provider founded in Casablanca by network, security and cloud engineers. Our articles draw on the projects we deliver for clients in Morocco and abroad.

LinkedIn
← All articles
CallWhatsAppFree audit