Home » IT Infrastructure » Wi-Fi, SD-WAN & Firewalls

Infrastructure — Edge

Firewall, Wi-Fi, and SD-WAN management for New York businesses

The edge is where your security policy meets the actual internet. Stedholm engineers firewalls, remote access, wireless, and multi-site connectivity from requirements — then reviews and monitors them like the critical systems they are.

A firewall is policy in packet form — and policy rots

Firewall rulebases grow the way attics fill: a rule for the vendor who needed access in 2021, an “any/any temporarily” that outlived three employees, port forwards for a system that was decommissioned. Every stale rule is attack surface, and firmware that lags behind advisories is the kind of finding that ends up in breach reports. The device most responsible for keeping the internet out is often the least maintained thing in the building.

Managed, for us, means a lifecycle: rules reviewed on a schedule with owners and expiry dates, firmware tracked against vendor advisories, high-availability pairs where the business case supports them, and logs feeding the monitoring our security practice works from. Remote access follows the same logic — VPN and zero-trust access tied to your identity platform and its Conditional Access policies, not to shared credentials; the identity side lives under Microsoft 365 administration.

This service is part of infrastructure services and sits on the LAN designed under network design and management.

What’s included

  • Firewall management

    Rule lifecycle with scheduled reviews, firmware currency, configuration backup before every change, and logging wired into monitoring — not into a void.

  • Remote access

    VPN and zero-trust network access bound to identity and MFA, with per-user policy instead of one tunnel that sees everything.

  • Wi-Fi engineering

    Coverage and density designed from surveys rather than guesswork, WPA3 or certificate-based enterprise authentication, and guest traffic kept firmly away from corporate.

  • SD-WAN

    Multi-site connectivity with circuit redundancy and automatic failover — dual internet paths that actually get tested, and application steering where it earns its keep.

  • Switching

    VLAN and port administration, PoE budgets that anticipate the cameras and phones, and lifecycle dates on a calendar instead of a surprise.

  • Continuous monitoring

    Edge devices, tunnels, and circuits watched around the clock by our tooling, with engineer escalation when something needs a human.

Multi-site is where the edge earns its keep

A second office changes the problem. Site-to-site connectivity, consistent firewall policy in two places, failover that works without a drive across the bridge — this is where accumulated networking breaks down and designed networking pays. SD-WAN with redundant circuits keeps a Tri-State firm on the air through the carrier outages that are a fact of life here.

It is also what insurers and client questionnaires increasingly probe: how remote access is authenticated, whether firmware is current, who reviews the rules. Running the edge properly turns those questions into short answers — and the evidence comes from the same monitoring and change records we operate every day. Office moves and new-site buildouts are scoped as projects; see locations for where we work.

  • Good fit if

  • Offices in NYC plus New Jersey or Connecticut

  • An office move or buildout on the calendar

  • Remote access still runs on a shared VPN login

  • Wi-Fi dead spots have become office folklore

  • Your insurer asked who manages the firewall

Common questions

Is a managed firewall the same as managed security?

No, and vendors blur this constantly. Firewall management is device hygiene: rules, firmware, backups, monitoring. Detection and response — someone investigating what the logs show — is a separate discipline, described under managed detection and response. We run both, and we keep the distinction honest.

Our Wi-Fi is slow in parts of the office. Can you fix it?

Usually, yes — and the fix starts with a survey, not with buying more access points. Most bad Wi-Fi is a design problem: wrong placement, wrong channels, too much power, or interference nobody measured. We measure first, then change what the measurements justify.

Which firewall and Wi-Fi vendors do you work with?

We standardize on a short list of proven platforms and choose per engagement based on requirements and budget — and we will tell you why we picked what we picked. What we avoid is running one of everything, because unmanaged variety is how edges rot.

We're opening a new office. When should we involve you?

Before the lease is signed, ideally — cabling, demarc location, and circuit lead times in the Tri-State area are easier to solve on a floor plan than in a finished space. New-site buildouts run as scoped projects under infrastructure services.

Take the folklore out of your edge.

An engineer will review your firewall rules, remote access, and wireless — and tell you what is current, what is stale, and what is risky.