Firewalls · Access control · Physical security · Peripherals

Security and peripherals: firewalls, access control and endpoint protection

Three distinct subjects that catalogues tend to mix: network security, physical access control to premises, and hardware protection of the endpoints themselves. We source Fortinet, Sophos, SonicWall, WatchGuard, HID Global, Kensington and Targus, and we help you avoid paying twice for the same function.

Firewalls: the appliance is not what costs

The listed price of an enterprise firewall is only part of the spend. Most of it sits in the security subscriptions: application filtering, encrypted traffic inspection, intrusion prevention, web filtering, sandboxing. These are sold as annual bundles, and their renewal represents, year after year, a sum comparable to the initial purchase price.

The second hidden item is sizing. A throughput figure quoted for raw firewalling bears no relation to throughput once encrypted traffic inspection is switched on: depending on the model the drop is substantial. An appliance chosen on raw throughput ends up saturated the day the features it was bought for are actually enabled.

We therefore always ask a supplier for two numbers: throughput with TLS inspection enabled on a representative security profile, and the three-year renewal cost of the subscriptions. Those are the only two values that allow an honest comparison between offers.

Segment before you buy

A firewall does not compensate for a flat architecture. In industrial and logistics environments, exposure rarely comes from the internet: it comes from internal equipment that cannot be patched at the pace of the rest of the estate — label printers, fixed readers, PLCs, production displays, payment terminals.

The rule administrators apply is simple: those devices go on dedicated VLANs, with explicitly authorised flows and nothing else. That segmentation costs configuration time and virtually nothing in hardware. It makes the firewall effective instead of turning it into a Maginot line.

The detail of that segmentation, including the port matrix for printing peripherals, is on our network equipment page.

Access control and badges: hardware, consumables and life cycle

A badge project is sized on three elements, not on the printer alone: card technology, encoding, and renewal.

Card technology determines compatibility with readers already installed. An existing reader estate imposes its standard; changing printer is easy, changing card technology means replacing the readers too. That is the first question to ask, before any quotation.

Encoding — magnetic stripe, contactless chip, visual personalisation — determines how the printer must be equipped. An encoding option added afterwards costs more than at order time, when it is possible at all.

Renewal, finally, is the recurring item: cards, ribbons, protective overlays. On a site of several hundred people with turnover, it outweighs the machine over three years.

Physical endpoint security: cheap, and usually forgotten

Security cables, docking station locks and lockable mounts almost never appear in an equipment budget. They become visible after the first theft.

Two points deserve attention. Anchor point compatibility: security slots vary between manufacturers and generations, and a universal cable is only universal on paper. And key management: across dozens of endpoints, a keyed-alike or master-key system avoids an unmanageable keyring and locks forced open for convenience.

Frequently asked questions

How do you compare two firewalls honestly?

On two numbers only: throughput with encrypted traffic inspection enabled on a realistic security profile, and the three-year renewal cost of the security subscriptions. Raw throughput and appliance price allow no useful comparison.

Is a firewall enough to secure a warehouse?

No. In these environments the main risk comes from unpatched internal equipment: printers, fixed readers, PLCs, payment terminals. Segmentation into dedicated VLANs with explicitly authorised flows is what makes the firewall effective.

Can we change badge printer without changing the readers?

Yes, as long as the card technology stays the same. The reverse is the problem: changing card technology forces the reader estate to be replaced too. That question belongs before the quotation, not after.

Are security cables universal?

No. Security slots vary between manufacturers and machine generations. On a mixed estate the anchor type has to be checked model by model, and a master-key system planned rather than one key per endpoint.

Do you source payment terminals?

Yes: Ingenico, Verifone and PAX Technology. They fall under the same network segmentation rules as other peripherals, with the added compliance constraints specific to payment.

See also