Firewall migration · Network discovery

Change firewalls with every rule accounted for.

Vis delivers fixed-scope firewall migrations and network discovery for in-house IT teams and MSPs. You get a cleaned-up rule base, a planned cutover with rollback, and documentation you own.

Vendor-neutral. Any platform pair. Based in Tennessee.

Services

Two packages, one outcome: a network you understand and control.

Firewall Migration

Move to a new firewall without carrying years of old problems onto it.

For end-of-support hardware, a platform change at renewal, a merger, or an insurance or audit finding. We work vendor-neutral, from any source platform to any target.

  • Rule cleanup findings: unused objects, shadowed or redundant rules, broad “any” rules and risky services. Nothing is removed without your written approval.
  • Migration report that accounts for every in-scope rule: converted, merged, removed with approval, or rebuilt by hand.
  • Written cutover plan with timings, go/no-go checks and rollback steps.
  • Validation of your critical applications after cutover, plus a hypercare period.
  • As-built documentation and a knowledge-transfer session for your team.

Packages are sized by firewall count, rule count and VPN tunnels. Starting at $3,500 for one firewall or HA pair, a standard rule base, and a written cutover plan with rollback steps. Assessment (from $750) and post-cutover check (from $500) are available as separate stages. Final price depends on scope.

Network Discovery

Know exactly what’s on your network, what’s out of support, and what to fix first.

For undocumented or inherited networks, and before a refresh, an office move, a merger or an insurance questionnaire. Discovery is read-only: we make no configuration changes.

  • Device inventory with hardware, software versions and lifecycle/support status.
  • Editable topology diagrams of how your network is actually connected.
  • Sanitized configuration backups, with passwords and keys removed.
  • Prioritized findings report: each finding with severity, evidence and a recommendation. Critical issues are reported the same day we find them.
  • A roadmap and readout meeting, with a sized next step instead of a vague “you should upgrade.”

Packages are sized by site and device count. Starting at $1,500 for one site, up to 100 devices, with a written inventory and findings report. Final price depends on scope.

How it works

A fixed scope, agreed up front. No surprises.

  1. Scope

    A short call and an intake questionnaire. You get a fixed-scope proposal listing exactly what’s included and what isn’t.

  2. Collect

    You provide read-only access or configuration exports. We agree access methods and change windows in writing first.

  3. Deliver

    We analyze, review findings with you, and, for migrations, cut over from a written plan with rollback steps.

  4. Hand over

    You receive the documentation, a readout or knowledge-transfer session, and a clear list of next steps.

If something outside the agreed scope comes up, we put it in writing with its cost, and no extra work starts until you approve it.

Why Vis

What you pay for is the outcome, not a converted config file.

Vendor-neutral

Any source and target platform. Our recommendations are based on your environment, not on a preferred brand.

Fixed scope, clear deliverables

Every package lists what you get and how we’ll both know it’s done. Out-of-scope work needs your written approval first.

You stay in control

No rule is removed without your sign-off. Discovery is read-only. Cutovers run in agreed windows with a rollback plan.

Documentation you own

Inventories, diagrams, sanitized configs and as-built notes are yours to keep and hand to anyone who runs the network next.

Cleanup is built in

Vendor tools can convert a config, but they copy its problems too. Rule cleanup is part of every migration, not an add-on.

One accountable contact

The same point of contact from intake through cutover and handover, so nothing gets lost between teams.

Contact

Let’s talk about your network.

Tell us what you’re running and what’s driving the change. In a free 20-minute call we’ll talk through where you stand and which package fits. No obligation.

Please don’t send passwords or configuration files by email. If we need them, we’ll arrange a secure way to share them.