AI training for Copilot, Claude and OpenAI. Book your slot now +61 3 4803 4915Client PortalRemote Support
Belton IT Nexus
Belton · Run / Protect / Improve / BuildView all services ›
Belton · Knowledge, not gatekeepingResource library ›
Belton IT Nexus · Est. 2004 · Newmarket, AucklandAbout us ›
Home/ Client guides/ Network, firewall & wifi
Client guide · shared with you by your Belton team · prices in NZD

Network security, properly done.

Your firewall is the front door of your business, and your wifi is how everyone gets in and out all day. This page walks you through how we survey, design, install and tune a secure network: what each phase involves, when the price is fixed, what happens on cutover night, and why the first fortnight afterwards is deliberately called tuning.

6 phasesfrom survey to handover Phase 3is where price is fixed Staged off-sitebefore anything is touched Old kit keptas the rollback
1A phase of the project
A decision that is yours to make
HOURSEffort estimate, agreed at scoping
Something we need from you
The journey

Six phases, one quiet cutover.

The map
1

The conversation

30 to 45 minutesNo charge

What is driving this: an office move or fit-out, wifi dead spots, kit that is out of support, an insurance or audit requirement, or a security review that named the network as a gap. The driver shapes the design, so we start there.

You leave withA clear next step, and an early sense of the scale involved.
2

Survey & audit

On site

We walk the site and map what is really there: every switch, access point and cable path, what is plugged into what, and how wifi actually performs room by room. On the security side we review the current firewall's rules and age, and what is exposed to the internet that should not be.

What we map
  • The physical network: switches, cabling, comms cabinet, access points
  • Wifi coverage and interference, measured, not guessed
  • Current firewall rules, age and support status
  • What is on the network that nobody remembers installing
What we need from you
  • Site access and a look inside the comms cabinet
  • A floor plan if one exists, even a rough one
  • The wifi complaints. All of them
Share of total effort~10 to 15%
You leave withA map of your network as it actually is, and the gaps ranked by risk.
3

Design & scoping: the plan and the price

Price is fixed here

We design the target network: the firewall platform and its security services, wifi coverage with access points placed from the survey rather than hope, and the network separated into zones so a compromise in one place cannot roam everywhere. The design becomes a fixed-price scope covering hardware, licensing and labour.

The scope names
  • Hardware, itemised: firewall, access points, switches, cabling work
  • Security subscriptions and their renewal costs, up front
  • Network zones: staff, guests, servers and devices kept apart
  • The cutover window and the rollback plan
What we need from you
  • The go decision on the design and price
  • Anything unusual we must keep working: EFTPOS, door controllers, CCTV, machinery
You leave withA fixed-price proposal, with ongoing subscription costs stated next to the one-off price.
Decision point · yours
Approve the design, the price and the window.

Nothing is ordered until you approve. Hardware lead times are included in the plan, so the dates you approve are dates that hold.

4

Staging

Off-site, zero disruption

The new firewall and access points are configured and tested on our bench before they come anywhere near your office. Rules, zones and wifi networks are built from the design, and tested against the odd things your site needs to keep working. Your network is untouched during this phase.

What happens
  • Firewall configured and its rules tested off-site
  • Access points pre-configured for their planned positions
  • The cutover checklist written: every step, every test, the rollback
Share of total effort~25 to 30%
5

Installation & cutover

Agreed windowUsually out of hours

Physical installation, then the switch: internet moves to the new firewall, wifi comes up on the new access points, and everything on the test checklist is proven before we leave. The old firewall stays racked and ready as the rollback until the new network has earned your sign-off.

In the window
  • New kit installed, old kit left in place as the fallback
  • Every zone, wifi network and critical device tested
  • EFTPOS, printers, door controllers and the awkward devices proven working
What we need from you
  • Site access for the window, and a contact we can reach
  • The new wifi password shared with your team, once, properly
Share of total effort~30 to 35%
6

Tuning & handover

The first fortnight

A new firewall is deliberately strict, so the first fortnight is a tuning period: if something your team legitimately needs gets blocked, that is a quick, expected fix, not a fight. Wifi gets a second measurement pass under real use. Then the documentation is finished and the network joins your managed environment: monitored, patched and watched from here on.

What ongoing looks like
  • Blocked-but-legitimate requests fixed fast during tuning
  • Firewall and access points monitored, updated and managed
  • Security subscriptions renewed on schedule, never silently lapsed
  • The network documented in your runbook, not in someone's head
Share of total effort~10%
The money

One-off, and ongoing.

Named at scoping

Network projects have a one-off build cost and a small set of ongoing costs. Both sit in the scope, so the decision you make at phase 3 is the whole picture.

Cost
What it is
Decided
Hardware
Firewall, access points, switches and any cabling work, itemised per device in the scope. Spread monthly through IT asset finance if that suits better than upfront.
At scoping, phase 3
Security subscriptions
Modern firewalls earn their keep through subscription services: threat intelligence, filtering, intrusion prevention. These renew annually, and the renewal price is in the scope from day one.
At scoping, phase 3
Labour
Survey, design, staging, installation and tuning, tagged to phases as hours, delivered for the fixed price you approved.
At scoping, phase 3
Ongoing management
Monitoring, updates and management of the network, usually folded into your managed services agreement so the network stays looked-after rather than installed-and-forgotten.
Agreed before handover
Two worked examples

One office, and many.

Sample plans
Sample plan A · smaller engagement
One office, refreshed.
A new firewall and wifi for a single office: coverage that reaches the meeting room, a guest network that is actually separate, and a front door that is no longer out of support.
2 to 3 weeksOne cutover evening
Survey & auditSite walk, wifi measured, rules reviewed
3 to 5 h
Design & scopingFixed price, zones, coverage plan
3 to 5 h
StagingConfigured and tested off-site
5 to 8 h
Installation & cutoverEvening window, full test checklist
6 to 10 h
Tuning & handoverFortnight of tuning, documentation
3 to 6 h
Indicative effort
~20 to 35 hours
Sample plan B · larger, complex build
Multi-site network security.
Firewalls and wifi across several sites, joined by secure site-to-site links, with the network split into zones and rolled out one site at a time so no single window carries all the risk.
1 to 3 monthsPer-site cutoversZoned network
Survey & auditEvery site walked and measured
12 to 24 h
Design & scopingOne design, all sites, fixed price
10 to 20 h
StagingEvery device configured and bench-tested
20 to 40 h
Installation & cutoversSite by site, each with rollback
30 to 60 h
Tuning & handoverCross-site tuning, full documentation
10 to 20 h
Indicative effort
~80 to 165 hours
These are illustrations, not quotes. Every site is different, and your project is scoped from a real survey with a fixed price before anything is ordered.
The deal

What you can hold us to.

Both ways
What you can expect from us
  • A design based on measurement, not guesswork
  • A fixed price, with subscription renewals stated up front
  • Everything staged and tested before your site is touched
  • The old firewall kept as the rollback until you sign off
  • Blocked-but-legitimate requests treated as quick fixes, not arguments
What we ask of you
  • Site access, and the truth about the wifi dead spots
  • The list of unusual devices that must keep working
  • A contact during the cutover window
  • Patience during the tuning fortnight, and every report of something blocked

Start with
the survey.

A conversation costs nothing, and the survey tells you what you are actually working with, whether or not you go ahead.

And relax

Getting started is the easy part.

Onboarding without drama

We do the switch: your current provider, the migration, the handover, all of it. Most teams barely notice the cutover happened.

Everything looked after

On the right plan, compliance, reporting and budgets are handled inside the partnership. You run the business; we run the IT underneath it.

Your QBR writes itself

Quarterly business reviews are generated automatically from your live environment: spend, posture, recommendations and roadmap, ready for the board, reviewed with your account manager.

The honest bit: the full looked-after experience comes with the right plan. We charge fairly for what we take on, and when costs step up it's because you are taking on more, always moving in the right direction.

Sovereign by design

New Zealand owned and operated.

Sovereign data centres across New Zealand and Australia, with your data kept onshore wherever it's required. Our team understands New Zealand, and our leaders have built, scaled and secured businesses right across the New Zealand landscape.

Sovereign data centres · New Zealand & Australia
  • Auckland
  • Christchurch
  • Sydney
  • Melbourne
  • Brisbane
  • Perth
International data-centre operations
  • Singapore
  • Germany
  • Netherlands
  • USA

Servers available in minutes, not days.

Explore data centres & hosting →
Partners & platforms
Microsoft Solutions Partner, Modern Work Microsoft Solutions Partner, Security
Fortinet Partner Veeam Partner Lenovo Partner HP Partner SentinelOne Partner Microsoft Azure Microsoft Copilot Claude
Book your free discovery & security session