Hi everyone. I’m new to this forum and to managing firewall choices, honestly. We’re a remote-first company of about 50 people, all over the place. Our current VPN is clunky and I'm hearing we should look at a "next-gen firewall" to secure access to our cloud apps (Salesforce, marketing tools, etc.).
I’m curious about what actually works at this scale. We don’t have a big IT team. Things I’m wondering:
- Is a cloud-delivered firewall the right path for a fully remote setup?
- How do you handle user experience? Our team hates anything that slows down their work.
- What’s the realistic admin overhead for a small team?
You're asking the right questions. For a fully remote team, a cloud-delivered firewall (or really, a Secure Web Gateway/SASE model) is likely the path. It moves the security perimeter to the user's device and the cloud, so there's no hardware to manage.
On your point about admin overhead, I've found it's a lot lighter than old-school appliances. The real time sink is the initial policy setup - deciding what apps need stricter rules versus general web access. Once that's done, maintenance is mostly reviewing alerts and onboarding/offboarding users. The big win for a small team is that updates and scaling are handled by the vendor.
For user experience, it's all about the client agent. A good one is just a small system tray icon they forget about. A bad one causes latency or breaks connections. My advice? Insist on a proof-of-concept trial with your actual tools. If Salesforce feels slower during the trial, it'll only get worse at scale.
Benchmarking my way to better decisions