Problem one
The unplanned refresh
Hardware reaches end of support on the vendor's schedule, not yours. The replacement arrives as an unplanned capital request in a year that has no room for it, so it gets deferred.
Network infrastructure
You should never have to buy a firewall again.
Enterprise network infrastructure on a monthly service. Fortinet hardware, leased and refreshed, centrally managed and monitored by a New Zealand team within Layer3's ISO/IEC 27001-certified ISMS.
Hardware
Leased and refreshed, not bought
Platform
Fortinet Security Fabric
Managed
FortiManager and FortiAnalyzer
Certified
ISO/IEC 27001:2022
Hardware
Leased and included in the monthly fee, refreshed at end of term. The lease runs with your managed services agreement, so the hardware term is the agreement term and longer terms price better. The hardware stays Layer3 property and returns at the end of service. Purchase is still available if owning the asset matters to you.
Platform
Fortinet Security Fabric as standard — FortiGate, FortiSwitch and FortiAP on one policy model, configured in FortiManager and logged to FortiAnalyzer. UniFi where the full fabric is not proportionate to the site.
What we run
Design and build, central configuration, firmware, monitoring, logging and reporting, multi-site connectivity, and the vendor and carrier relationships — not a contract you call when something breaks.
Where it ends
The physical estate: firewalls, switching, wireless, site-to-site links and the sites themselves. Secure access for people working away from a site sits above this, in the Secure Edge tier.
Cabling
Internal wiring, mounting and cabling remain your responsibility. We plan it, specify it, and can arrange a contractor. Onsite installation at regional locations may carry additional cost.
Buying it on its own
Managed Network can be bought without managed IT, and often is. It works better alongside managed or co-managed IT, but it does not depend on it.
01
The case for change
Most organisations make it under budget pressure, then live with the consequences. Network hardware is bought once, capitalised, and then quietly ages while the threat landscape does not. By the time the refresh is due, the money has been spent elsewhere and the device is still passing traffic - which is exactly the problem.
Problem one
Hardware reaches end of support on the vendor's schedule, not yours. The replacement arrives as an unplanned capital request in a year that has no room for it, so it gets deferred.
Problem two
An unsupported firewall stops receiving firmware and threat intelligence updates. It keeps working, and that is what makes it dangerous - nothing visibly fails.
Problem three
Device-by-device changes made by whoever was available, with no baseline and no version history. When that person leaves, the rule set becomes an archaeology exercise.
The model
The hardware is included in your monthly fee and refreshed at end of term. There is no capital request, no depreciation schedule, and no refresh project sitting on your roadmap.
Buying it yourself
A capital approval, a specification chosen for the traffic you have today, and a depreciation schedule. When support ends, the replacement project is yours to fund, scope and run.
Leasing it from us
Hardware, licensing, management and monitoring in one monthly figure. We track end of support, we fund the refresh, and we swap the device. The asset stays ours and comes back to us at the end of service.
The lease runs with your managed services agreement — the hardware term is the agreement term, and longer terms price better. Buying is still available if owning the asset matters to you. Most clients decide it does not.
The stack
We build on the Fortinet Security Fabric as standard. Firewall, switching and wireless from one vendor means one policy model, one log store and no blind spots between three management consoles.
01
The next-generation firewall at every site. Traffic inspection, network segmentation, site-to-site tunnels and policy enforcement at the edge.
02
Managed switching that joins the same fabric, so port-level policy follows the device rather than depending on which socket someone plugged into.
03
Wireless access points managed from the same console, with SSIDs, guest isolation and access policy applied consistently across every site.
04
One console for configuration and policy across every device and every site. Changes are versioned, reviewed and rolled out centrally, not typed into a device at 4pm on a Friday.
05
Centralised logging and analytics. What happened, when, on which device, retained for as long as your policy or your insurer requires.
06
Where the full fabric is not proportionate to the site, we build on UniFi instead. Smaller footprint, lower cost, same management discipline and the same monitoring.
The service
Not a support contract you call when something breaks. The network is operated as a managed estate, with the work happening whether or not you have noticed a problem.
Design and build
Site survey, addressing, segmentation and resilience, documented and signed off before anything is racked.
Configuration
Policy and configuration held centrally in FortiManager, versioned and backed up. Standard changes are made by us on request, against the documented baseline.
Firmware
Maintained on a managed schedule and tested before it reaches production, so devices stay in support and in policy.
Monitoring
Device health, link state and traffic monitored continuously. In most cases we know about the outage before your phone rings.
Logging and reporting
FortiAnalyzer retains the event history, with reporting on utilisation, threats blocked and availability against the period.
Multi-site connectivity
Site-to-site tunnels and inter-site routing managed as one estate rather than a collection of independent boxes that happen to be connected.
Vendor and carrier coordination
We hold the vendor and carrier relationships and chase the fault, so your team is not the one sitting on hold to an ISP.
Scope
Managed Network covers the physical estate - the boxes, the links and the sites. Secure access for people working outside those sites is a different problem, and it sits in a different part of our service.
Edge
Firewalls, segmentation and policy at every site.
Access layer
Switching and wireless, configured and monitored as one estate.
Between sites
Site-to-site tunnels, routing and carrier coordination.
Visibility
Monitoring, centralised logging and reporting on the network estate.
Secure access
SASE cloud firewall and secure access policy for people working away from a site.
Zero Trust
Zero Trust network access replacing the traditional VPN, so access follows the person and the device.
Correlation
Network telemetry integrated with endpoint and identity signal in a wider SIEM.
Where
These sit in the Secure Edge tier of our managed plans, layered over the network below.
Internal wiring, mounting and cabling sit outside the service. We plan and specify them, and can arrange a contractor.
Transition
Network cutovers are the ones people fear, because a mistake takes everybody offline at once. So we stage everything first and we always keep a way back.
01
Survey
Sites, links, existing hardware, what is still in support and what is not. Usually the first time an organisation sees the whole estate written down.
02
Design
Addressing, segmentation, resilience and firewall policy, documented and agreed with you before any hardware is ordered.
03
Stage
Devices configured, licensed and tested in our workshop, then registered into FortiManager so they arrive on site already knowing their policy.
04
Cutover
Scheduled around your operating hours, usually out of hours, with the old configuration retained and a defined rollback point at every stage.
05
Operate
Monitoring, firmware, changes and reporting from day one, reviewed on a set cadence and refreshed when the hardware reaches end of term.
Track record
Layer3 has supported New Zealand organisations since 2005, including multi-site operators where the network being down means the business is down.
Operating since 2005
21 Years
Two decades designing and running networks for organisations that cannot afford to be offline.
The team
20+ Staff
Engineers based in New Zealand, who can be on your site rather than on a plane.
Security operations
24/7
For SOC customers, network events are monitored and responded to outside business hours.
Independently audited
ISO 27001
The network service is delivered within Layer3's ISO/IEC 27001-certified ISMS and run to documented controls.

Client work
Customer example
First test: the firewall
The New Zealand Police Association came to Layer3 with a firewall at end of life and a distributed workforce of 60 people. Service requests have halved since.
Read the New Zealand Police Association case studyCommon questions
The questions we get asked most often about leased hardware, the Fortinet stack and what happens at end of term. If yours is not here, ask us directly.
Book a discovery callBy default, no. The hardware is leased, included in your monthly fee, and remains Layer3 property - it returns to us at the end of service. That is what lets us fund the refresh rather than asking you to. If owning the asset matters to your balance sheet, purchase is still available.
We replace it. Tracking end-of-support dates and funding the refresh is our responsibility under the leased model, not a capital request that lands on your desk. This is the single biggest reason organisations move to it.
Usually, yes - subject to the devices being in support and on a firmware version we can safely manage. Where they are not, we will tell you what needs replacing and when, rather than inheriting a problem quietly.
One fabric, one policy model, one log store. Running firewall, switching and wireless from three different vendors means three consoles, three upgrade cycles and blind spots in between. FortiManager and FortiAnalyzer give us central configuration and central logging across every site.
Where the full Security Fabric is not proportionate to the site - smaller offices, simpler requirements, or where the cost of the fabric cannot be justified. The management discipline and the monitoring stay the same.
Internal wiring, mounting and cabling remain your responsibility. We plan and specify it, and we can arrange a contractor. Additional costs may apply for onsite installation at regional locations.
Site-to-site connectivity between your locations is included. Secure access for people working away from a site - SASE and Zero Trust network access replacing the traditional VPN - sits above this in the Secure Edge tier of our managed plans.
No. Managed Network can be bought on its own, and often is by organisations who get their day-to-day IT support elsewhere or run it in house. It works better alongside managed or co-managed IT, but it does not depend on it.
Start the conversation
A survey of your sites, links and hardware, with a documented assessment of what remains supported and what needs attention. No obligation.

Layer3 is a managed IT provider operating an ISO/IEC 27001-certified ISMS, with offices across New Zealand.
Contact
0508 LAYER3 Book a discovery call Service status Notices
Level 2, CBD Towers
84-90 Main Street
Upper Hutt, Wellington 5018
Layer3
Book a discovery call - 30 minutes, no obligation