What MSPs should look for in a firewall
Running firewalls for dozens of customers is a different job from running one. Here is what actually matters at that scale.
An MSP, a managed service provider, runs IT for other businesses. Picking a firewall for one customer is easy. Picking one to standardise on across fifty customers is a different, harder decision, and the wrong choice costs hours every week.
Fleet management, not one-at-a-time management
If every customer firewall has to be opened and managed separately, that cost multiplies with every new customer you sign. A firewall built for MSPs should let you see every customer's firewall from one screen, and act on many of them at once.
- One dashboard listing every customer site, its status, and anything that needs attention.
- The ability to push the same rule, or the same update, to a group of customers at once.
- Alerts that reach you, not a dashboard nobody is watching.
Remote management that does not open new risk
Managing a customer's firewall remotely usually used to mean opening an inbound hole in their firewall, so your management traffic could reach in from outside. That hole is itself a risk, sitting there permanently, whether you are actively managing that site or not.
A better pattern flips the connection around. The customer's firewall reaches out to your management platform, using an outbound connection it starts itself. Nothing has to be opened facing the internet on the customer's side at all.
Real separation between customers
Every customer's traffic, rules, and logs need to stay genuinely separate from every other customer's. This matters for two reasons: a mistake made on one customer's firewall should never touch another's, and one customer should never be able to see another customer's data, even by accident.
This is often called multi-tenant support: one platform, but every customer's configuration kept in its own walled-off space, not just visually separated on the same screen.
Technician access levels
Not every technician on your team should be able to do everything. A new hire on the help desk should be able to look up a customer's status. A senior engineer should be able to change firewall rules. These are different levels of trust, and the platform should let you set that difference, known as RBAC, per person.
- Junior technicians: view status and basic reports, no ability to change rules.
- Senior technicians: full access to the customers they are assigned to.
- Admins: access across the whole fleet, including billing and licensing.
This also matters when staff leave. Access tied to a person, not shared logins passed between employees, means removing one departing technician does not require rebuilding passwords across every customer they ever touched.
Standardised configs across every customer
Rebuilding a firewall's configuration by hand for every new customer wastes time and invites mistakes. A firewall platform aimed at MSPs should let you define a standard template, VLANs, firewall rules, VPN settings, once, and apply it to a new customer in minutes rather than hours.
Config as code, keeping settings in a file you can store, review, and reapply, makes this easier still. A change reviewed once can be rolled out to every customer running that template, instead of being retyped by hand at each one.
Licensing that works at scale, and actual margin
Some vendors price per feature, per user, or per site, in ways that only become clear once you have already signed dozens of customers up. That model can quietly erode the margin an MSP depends on.
- Ask for the real price at ten customers, and again at fifty, not just at one.
- Ask whether adding VPN users or extra sites changes the price per customer.
- Ask whether there is a partner or reseller margin built in, rather than reselling at cost.
What Firecradle gives an MSP
Firecradle's fleet management shows every customer site from one dashboard, with outbound-only remote management so nothing has to be opened on a customer's network. Role-based access lets you set exactly what each technician can touch, and per-customer separation keeps every account genuinely walled off from the others. Reseller pricing is built in, not bolted on.