Skip to main content
For MSPs

You run networks for many clients. Firecradle was built for that.

A Managed Service Provider looks after other people’s networks all day. Firecradle gives you one console for every site, without ever opening a hole in a client’s firewall to get it.

Outbound-only fleet agent · command allowlist · one console

The problems every MSP already knows

None of these are hypothetical. They are the reasons managing many firewalls badly gets expensive.

Too many consoles
Every vendor wants you in a different screen. You end up checking ten tabs just to see if your sites are healthy.
Opening a hole is a liability
Remote management often means opening a port in a client’s firewall. If that hole is ever misused, it is your name on the ticket.
New technicians need guardrails
You cannot let a first-week hire touch every client’s firewall the same way your lead engineer can.
Clients want to see the value
You do the work every month, but if nobody can show it on a screen, it is hard to charge for it.

One console, and no open door

This is the part that matters most. The Firecradle in a client’s office calls out to you. You never call in.

Outbound-only fleet agent
Each Firecradle calls out to your console over an encrypted connection. Your console never calls in, so there is no port to open and no hole in the client’s firewall.
A command allowlist
The console can only ask for a short list of safe actions, like a health check or a report. It cannot send an unknown command and have the box just run it.
Remote config, off by default
Even your own console cannot silently rewrite a client’s firewall rules. An admin at that site has to switch this on first.
One console for every site
See every client site, its health, and its alerts, in one screen instead of forty separate logins.
Roles for every technician
Give a junior tech a look-only view. Give your lead engineer the keys. Role-based access decides who can do what.
Standard configs, applied everywhere
Write a setup once and roll it out to every client who should have it, using config as code. More on the command line and config as code.
Firecradle MSP fleet console listing multiple client sites with a health status, last check-in time, and alert count for each
Every site your team manages, in one screen. Each one called out to get here — nobody called in.

Every client stays in their own lane

Managing many sites from one login only works if the sites never mix.

0
inbound ports opened by the fleet agent
Allowlist
of safe commands the console is permitted to send
Off by default
remote config gate, until a client admin turns it on
One
login for every client site you manage

Turn management into margin

Managing a client’s network well is worth paying for. Firecradle is built to help you show that.

Sell it under your own plan
Package Firecradle into your managed-services plan and set your own margin. See reselling Firecradle.
Marketing already written for you
Use ready-made pitch material to explain the fleet agent story to your own clients. See MSP marketing tools.
One vendor bill, not forty
Appliance pricing is per site and predictable, so quoting a new client only takes a minute.

How MSPs actually use this

Onboarding a new client site in under an hour

The problem: A new client signs up. The technician you send has never seen this network before today.

What Firecradle does:
A guided setup wizard walks the tech through the basics
The site enrolls in your fleet console with a one-time code
The console shows the site is healthy within minutes
No inbound port ever had to be opened on the client’s router

A junior technician who cannot break anything

The problem: You want a junior tech running daily checks, but not touching firewall rules yet.

What Firecradle does:
Give the technician a look-only role
They can see alerts and health across every site they support
Rule changes stay reserved for senior engineers
Nothing they click can rewrite a client’s firewall by accident

Built for managing many networks at once

Everything here ships in the appliance

A fleet agent that only ever connects outward, over an encrypted channel
A command allowlist — health checks and reports, nothing else, by default
A remote-config gate that is off until a client admin turns it on
One dashboard across every client site you manage
Role-based access so a junior tech and a senior engineer see different things
Standard configs applied across many clients with config as code
Per-site, predictable appliance pricing
A reselling program with your own margin

Common questions

Does the fleet agent open any ports on a client’s firewall?

No. Every connection is outbound from the appliance to your console. Nothing new ever listens for inbound traffic, so there is no port to forward and no hole to defend.

Can my console push a firewall change to a client without them knowing?

No. Remote configuration is switched off by default on every site. An admin at that client has to turn it on before your console can push a change to their firewall.

Can I give different technicians different levels of access?

Yes. Role-based access lets you decide who can only view a site and who can change its settings, so a junior hire cannot do what a senior engineer can.

Can I resell Firecradle under my own brand and pricing?

Yes. MSPs can package Firecradle into their own plans and set their own margin. See the reselling program for how that works.

Manage every client from one screen

No open ports, a command allowlist, and a remote-config gate that stays off until you say so. Try it free for 30 days.

No credit card required · Cancel anytime · 30-day free trial