Skip to content

Field note / network and connectivity

Someone has to own the firewall. It should not be whoever answers the phone first.

Firewall administration, Wi-Fi management, VPN and remote-access support, and basic SD-WAN oversight are common recurring requests that do not fit neatly inside user support or endpoint management. Qualified on their own, they become a defined lane instead of an improvised favour.

Why this needs its own boundary

Connectivity dealers raise this question first - but it applies more broadly.

A telecom or office-equipment dealer's technicians are often physically present when a firewall or access point gets installed, which raises an obvious question: does that presence extend into ongoing administration? The honest answer is that it can, once the boundary between the connectivity drop and the managed network is written down, the same way any other lane is qualified. The same lane applies just as often to agencies and consultants whose clients simply have a firewall, a Wi-Fi network, and a VPN nobody has formally taken ownership of.

Read the connectivity-dealer boundary question this resolves →

Coverage area

Firewall administration

An existing firewall needs ongoing rule review and change handling.

Included pattern
Routine rule review, firmware updates, and configuration change requests within an agreed device set.
Required inputs
Device make and model, current configuration access, and change-approval expectations.
Explicit exclusions
Replacing failed hardware or negotiating the underlying connectivity contract.

Coverage area

Wi-Fi management

Access points and guest policy need a named owner across a site.

Included pattern
Access-point configuration, guest-network policy, and coverage troubleshooting within a defined site.
Required inputs
Access-point inventory, controller or cloud-management access, and site layout basics.
Explicit exclusions
Physical cabling, mounting, or a coverage guarantee before a site is surveyed.

Coverage area

VPN and remote access

An existing remote-access or site-to-site VPN needs ongoing administration.

Included pattern
User and policy administration for an existing remote-access or site-to-site VPN.
Required inputs
The VPN platform in use and current authentication method.
Explicit exclusions
Designing a new remote-access architecture without a separate scoping step.

Coverage area

SD-WAN and multi-site oversight

Multiple sites already share a deployed SD-WAN platform.

Included pattern
Configuration follow-up and change requests across an already-deployed SD-WAN platform.
Required inputs
Site count, the SD-WAN vendor, and current management access.
Explicit exclusions
Circuit procurement or carrier-contract negotiation, which stays outside this lane.

Boundary table

Where the connectivity contract ends and this lane begins.

QuestionWhy the public bands cannot answer itWhere it gets answered
Where does the connectivity contract end and this lane begin?That boundary depends entirely on what a specific dealer or ISP contract already covers.Written into the service boundary record before either side assumes coverage.
What happens when the internet itself is down?Circuit and ISP-side troubleshooting is a vendor dependency, not a network-administration task.Routed through the vendor-escalation path, not this lane.
Who approves a firewall rule change?Change authority for anything client-impacting needs a named owner, same as any other request type.Assigned in the responsibility matrix.
Is this lane available to a connectivity or hardware dealer?Yes, once the existing hardware or connectivity contract's boundary is explicit.Confirmed during partner-fit qualification.

What not to promise yet

Keep the offer honest until the site is surveyed.

  • A guaranteed Wi-Fi coverage result before a site survey
  • Responsibility for an ISP or carrier outage
  • A security guarantee tied to firewall administration alone
  • Same-day onsite response without a written coverage term
  • Network design for an environment nobody has documented

Review how an ISP or carrier dependency is escalated →

Related decision

Voice traffic runs on this same network.

Hosted VoIP and Teams Phone administration is a separate, qualifiable lane - distinct from the network itself.

Review the VoIP and Teams Phone lane

Bring the device list, not a network diagram.

A plain inventory of firewalls, access points, and VPN endpoints is enough for an initial fit review.

Discuss a network management lane