Layer3 Logo

Network infrastructure

Managed network

You should never have to buy a firewall again.

Enterprise network infrastructure on a monthly service. Fortinet hardware, leased and refreshed, centrally managed and monitored by a New Zealand team within Layer3's ISO/IEC 27001-certified ISMS.

Hardware

Leased and refreshed, not bought

Platform

Fortinet Security Fabric

Managed

FortiManager and FortiAnalyzer

Certified

ISO/IEC 27001:2022

At a glance — how the network service works

Hardware

Leased and included in the monthly fee, refreshed at end of term. The lease runs with your managed services agreement, so the hardware term is the agreement term and longer terms price better. The hardware stays Layer3 property and returns at the end of service. Purchase is still available if owning the asset matters to you.

Platform

Fortinet Security Fabric as standard — FortiGate, FortiSwitch and FortiAP on one policy model, configured in FortiManager and logged to FortiAnalyzer. UniFi where the full fabric is not proportionate to the site.

What we run

Design and build, central configuration, firmware, monitoring, logging and reporting, multi-site connectivity, and the vendor and carrier relationships — not a contract you call when something breaks.

Where it ends

The physical estate: firewalls, switching, wireless, site-to-site links and the sites themselves. Secure access for people working away from a site sits above this, in the Secure Edge tier.

Cabling

Internal wiring, mounting and cabling remain your responsibility. We plan it, specify it, and can arrange a contractor. Onsite installation at regional locations may carry additional cost.

Buying it on its own

Managed Network can be bought without managed IT, and often is. It works better alongside managed or co-managed IT, but it does not depend on it.

01

The case for change

A five-year commitment, made in a week

Most organisations make it under budget pressure, then live with the consequences. Network hardware is bought once, capitalised, and then quietly ages while the threat landscape does not. By the time the refresh is due, the money has been spent elsewhere and the device is still passing traffic - which is exactly the problem.

Problem one

The unplanned refresh

Hardware reaches end of support on the vendor's schedule, not yours. The replacement arrives as an unplanned capital request in a year that has no room for it, so it gets deferred.

Problem two

Security that quietly ages out

An unsupported firewall stops receiving firmware and threat intelligence updates. It keeps working, and that is what makes it dangerous - nothing visibly fails.

Problem three

Configuration in one person's head

Device-by-device changes made by whoever was available, with no baseline and no version history. When that person leaves, the rule set becomes an archaeology exercise.

The model

Hardware as a service

The hardware is included in your monthly fee and refreshed at end of term. There is no capital request, no depreciation schedule, and no refresh project sitting on your roadmap.

Buying it yourself

A five-year bet, paid up front

A capital approval, a specification chosen for the traffic you have today, and a depreciation schedule. When support ends, the replacement project is yours to fund, scope and run.

Leasing it from us

Operating cost, refreshed on our schedule

Hardware, licensing, management and monitoring in one monthly figure. We track end of support, we fund the refresh, and we swap the device. The asset stays ours and comes back to us at the end of service.

The lease runs with your managed services agreement — the hardware term is the agreement term, and longer terms price better. Buying is still available if owning the asset matters to you. Most clients decide it does not.

The stack

One fabric, one console

We build on the Fortinet Security Fabric as standard. Firewall, switching and wireless from one vendor means one policy model, one log store and no blind spots between three management consoles.

01

FortiGate

The next-generation firewall at every site. Traffic inspection, network segmentation, site-to-site tunnels and policy enforcement at the edge.

02

FortiSwitch

Managed switching that joins the same fabric, so port-level policy follows the device rather than depending on which socket someone plugged into.

03

FortiAP

Wireless access points managed from the same console, with SSIDs, guest isolation and access policy applied consistently across every site.

04

FortiManager

One console for configuration and policy across every device and every site. Changes are versioned, reviewed and rolled out centrally, not typed into a device at 4pm on a Friday.

05

FortiAnalyzer

Centralised logging and analytics. What happened, when, on which device, retained for as long as your policy or your insurer requires.

06

UniFi, where it fits

Where the full fabric is not proportionate to the site, we build on UniFi instead. Smaller footprint, lower cost, same management discipline and the same monitoring.

The service

What we manage

Not a support contract you call when something breaks. The network is operated as a managed estate, with the work happening whether or not you have noticed a problem.

Design and build

Site survey, addressing, segmentation and resilience, documented and signed off before anything is racked.

Configuration

Policy and configuration held centrally in FortiManager, versioned and backed up. Standard changes are made by us on request, against the documented baseline.

Firmware

Maintained on a managed schedule and tested before it reaches production, so devices stay in support and in policy.

Monitoring

Device health, link state and traffic monitored continuously. In most cases we know about the outage before your phone rings.

Logging and reporting

FortiAnalyzer retains the event history, with reporting on utilisation, threats blocked and availability against the period.

Multi-site connectivity

Site-to-site tunnels and inter-site routing managed as one estate rather than a collection of independent boxes that happen to be connected.

Vendor and carrier coordination

We hold the vendor and carrier relationships and chase the fault, so your team is not the one sitting on hold to an ISP.

Scope

Where the network ends

Managed Network covers the physical estate - the boxes, the links and the sites. Secure access for people working outside those sites is a different problem, and it sits in a different part of our service.

In scope here

Edge

Firewalls, segmentation and policy at every site.

Access layer

Switching and wireless, configured and monitored as one estate.

Between sites

Site-to-site tunnels, routing and carrier coordination.

Visibility

Monitoring, centralised logging and reporting on the network estate.

Sits above this

Secure access

SASE cloud firewall and secure access policy for people working away from a site.

Zero Trust

Zero Trust network access replacing the traditional VPN, so access follows the person and the device.

Correlation

Network telemetry integrated with endpoint and identity signal in a wider SIEM.

Where

These sit in the Secure Edge tier of our managed plans, layered over the network below.

Internal wiring, mounting and cabling sit outside the service. We plan and specify them, and can arrange a contractor.

Transition

How we take it on

Network cutovers are the ones people fear, because a mistake takes everybody offline at once. So we stage everything first and we always keep a way back.

01

Survey

What is currently in place

Sites, links, existing hardware, what is still in support and what is not. Usually the first time an organisation sees the whole estate written down.

02

Design

Written and signed off

Addressing, segmentation, resilience and firewall policy, documented and agreed with you before any hardware is ordered.

03

Stage

Built before it ships

Devices configured, licensed and tested in our workshop, then registered into FortiManager so they arrive on site already knowing their policy.

04

Cutover

Planned, with a way back

Scheduled around your operating hours, usually out of hours, with the old configuration retained and a defined rollback point at every stage.

05

Operate

Monitored and reviewed

Monitoring, firmware, changes and reporting from day one, reviewed on a set cadence and refreshed when the hardware reaches end of term.

Track record

Who is holding the network

Layer3 has supported New Zealand organisations since 2005, including multi-site operators where the network being down means the business is down.

Operating since 2005

21 Years

Two decades designing and running networks for organisations that cannot afford to be offline.

The team

20+ Staff

Engineers based in New Zealand, who can be on your site rather than on a plane.

Security operations

24/7

For SOC customers, network events are monitored and responded to outside business hours.

Independently audited

ISO 27001

The network service is delivered within Layer3's ISO/IEC 27001-certified ISMS and run to documented controls.

ISO/IEC 27001 certification mark

Client work

What this looks like in practice

Common questions

Before you ask

The questions we get asked most often about leased hardware, the Fortinet stack and what happens at end of term. If yours is not here, ask us directly.

Book a discovery call

By default, no. The hardware is leased, included in your monthly fee, and remains Layer3 property - it returns to us at the end of service. That is what lets us fund the refresh rather than asking you to. If owning the asset matters to your balance sheet, purchase is still available.

We replace it. Tracking end-of-support dates and funding the refresh is our responsibility under the leased model, not a capital request that lands on your desk. This is the single biggest reason organisations move to it.

Usually, yes - subject to the devices being in support and on a firmware version we can safely manage. Where they are not, we will tell you what needs replacing and when, rather than inheriting a problem quietly.

One fabric, one policy model, one log store. Running firewall, switching and wireless from three different vendors means three consoles, three upgrade cycles and blind spots in between. FortiManager and FortiAnalyzer give us central configuration and central logging across every site.

Where the full Security Fabric is not proportionate to the site - smaller offices, simpler requirements, or where the cost of the fabric cannot be justified. The management discipline and the monitoring stay the same.

Internal wiring, mounting and cabling remain your responsibility. We plan and specify it, and we can arrange a contractor. Additional costs may apply for onsite installation at regional locations.

Site-to-site connectivity between your locations is included. Secure access for people working away from a site - SASE and Zero Trust network access replacing the traditional VPN - sits above this in the Secure Edge tier of our managed plans.

See the plan ladder.

No. Managed Network can be bought on its own, and often is by organisations who get their day-to-day IT support elsewhere or run it in house. It works better alongside managed or co-managed IT, but it does not depend on it.

Start the conversation

Find out what you are running

A survey of your sites, links and hardware, with a documented assessment of what remains supported and what needs attention. No obligation.

Layer3

Book a discovery call - 30 minutes, no obligation