Multi-Site Firewall
About the client
Our client, Alpi UK Ltd, is a multi-site organisation operating across five locations, including four UK sites and one European site in Poland. With approximately 200 users, the business relies heavily on secure and stable connectivity between offices and cloud platforms to support day-to-day operations.

Challenges faced
The client’s existing Sophos firewall estate had developed inconsistencies over time due to organic growth and differing site requirements. This led to several challenges:
Lack of standardisation across firewall configurations
Reduced performance at certain sites
Increased complexity when managing policies and troubleshooting issues
Limited centralised visibility across the network estate
Operational difficulty supporting an international site (Poland) remotely
The client required a modern, standardised solution that would improve performance, simplify management, and support seamless multi-site connectivity.
Our process
The deployment was carried out using a carefully planned phased approach to minimise disruption:
Pre-configured and fully tested in advance
Firewalls were pre-configured and fully tested prior to deployment, ensuring each appliance was ready to go live with minimal on-site work required.
Sequential UK migration outside business hours
UK sites were migrated sequentially, primarily outside of business hours. Existing configurations were rationalised and standardised during the transition.
International deployment – the Poland site
To overcome logistical challenges, the firewall for the Poland site was:
- fully pre-configured and validated in advance.
- shipped directly to the site with clear, step-by-step plug-in instructions.
- designed for rapid on-site installation by non-technical staff if required.
This approach enabled a smooth and efficient international rollout without the need for on-site engineering presence.
Site-to-site VPN connectivity established
Site-to-site VPN connectivity was then established using a consistent framework, ensuring secure and reliable inter-office communication.
The solution
We designed and deployed a standardised firewall solution using WatchGuard Firebox appliances across all five sites. The solution included:
WatchGuard Firebox at every location
Deployment of WatchGuard Firebox appliances at each location
Secure site-to-site VPN connectivity
Secure site-to-site VPN connectivity between all UK and Polish sites
Centralised management
Centralised management via WatchGuard Cloud
Standardised policies
Standardised firewall policies, NAT rules, and security services
Enhanced monitoring & centralised logging
Enhanced monitoring and reporting through centralised logging
The design ensured consistency across all locations while maintaining flexibility to support site-specific requirements.
Key outcomes
The deployment delivered measurable improvements across the organisation:
Improved performance
Improved performance across all locations, particularly for inter-site traffic.
Reliable, stable VPN connectivity
Reliable and stable VPN connectivity between UK and European sites.
Standardised firewall configuration
Standardised firewall configuration, reducing complexity and risk.
Centralised management
Centralised management, significantly lowering administrative overhead.
Enhanced visibility and monitoring
Enhanced visibility and monitoring, enabling faster troubleshooting.
Simplified international support model
Simplified international support model, removing the need for on-site intervention.
The new solution provides a scalable and secure foundation, supporting both current operations and future expansion.



