Headquartered in Coquitlam. Serving Greater Vancouver.
Get IT Help

Firewall Engineering

Firewall Blocking Apps or Slowing Your Network? The 5 Misconfigurations We Find Most

A firewall should be invisible when you're working and impenetrable when you're attacked. When Teams calls stutter, cloud apps time out, or the internet 'feels slow,' the firewall is a prime suspect - usually because of how it was configured, not the brand on the box.

By  8 min read Published July 7, 2026

Fast answer

The five most common firewall problems we find on assessments: hardware undersized for full inspection throughput, SSL inspection breaking specific applications, years of accumulated rules nobody dares delete, misconfigured SD-WAN or failover that flaps connections, and firmware so old it misses both security fixes and performance improvements. Every one is diagnosable with data.

1. The throughput number on the datasheet isn't real

Firewall vendors quote raw throughput, but turn on the features you actually bought it for - intrusion prevention, antivirus, web filtering, SSL inspection - and effective throughput can drop by 80-a large share. A firewall sold for a 100 Mbps office connection quietly becomes the bottleneck when the office upgrades to gigabit fibre.

The check: compare your ISP speed with inspection features on versus off. If the gap is dramatic, the box is undersized for the way you use it. Sizing correctly is a core part of our firewall engineering work.

2. SSL inspection breaking apps in ways nobody connects to the firewall

Modern traffic is encrypted, so serious inspection means the firewall decrypts and re-encrypts sessions. Done properly, it's invisible. Done carelessly, it breaks applications that use certificate pinning - banking tools, some Microsoft 365 features, EMR clients, payment terminals - with error messages that look nothing like a firewall problem.

The fix: a maintained exemption list for pinned applications, a properly deployed inspection certificate on every managed device, and change control so inspection policy updates are tested, not YOLO'd on a Friday.

3. Rule sprawl: the config nobody dares touch

Every firewall we inherit tells the same story: temporary rules made permanent, vendor access opened for a project that ended in 2021, an "allow any" placed during an outage and never removed. Sprawl hurts twice - the permissive rules are security holes, and the sheer rule count slows evaluation and makes every change riskier.

The fix: a rule audit with hit counters (rules with zero hits in 90 days are candidates for removal), documentation of what each surviving rule is for, and a naming convention so the next engineer isn't archaeology-ing your security policy.

4. Failover and SD-WAN that make things worse

Dual internet connections are only as good as the failover logic. Misconfigured link monitors flap between connections on transient blips, dropping every VoIP call and VPN tunnel each time. Some setups fail over correctly but never fail back, leaving the office on the slow backup line for weeks without anyone realizing.

The fix: tuned health checks with realistic thresholds, session-aware failover so calls survive a switch, and monitoring that alerts when you're running on backup - because silent degradation is still degradation.

5. Firmware from two years ago

Firewalls are the most attacked device category on the internet - exploitable firewall vulnerabilities are how several of the ransomware incidents in BC we've been called into began. But updates also fix performance and stability bugs, so stale firmware means you're slower and exposed.

The fix: a maintenance schedule with tested updates during defined windows, and configuration backups before every change so rollback is minutes, not hours. Expert-level Fortinet credentials support the disciplined change process behind this work.

FAQ

Firewall FAQ

How do I know if the firewall is what's slowing us down?

Measure throughput with inspection on and off, and check CPU/session load during busy hours. It's an hour of diagnostics, not guesswork.

Should we just buy a bigger firewall?

Sometimes - but half the slow firewalls we see are adequately sized and badly configured. Audit first, buy second.

How often should firewall rules be reviewed?

Quarterly reviews with hit-count data, plus immediate cleanup after any vendor or project ends. If it's been years, start with a full audit.

Can you audit our firewall without disrupting the office?

Yes. Assessment is read-only. Any changes that come out of it are scheduled in maintenance windows with rollback plans.

When Did Someone Last Actually Look at Your Firewall?

Get a fixed-fee firewall assessment covering sizing, rule review, and prioritized fixes with expert-level Fortinet oversight.

About NYRO Dynamics

NYRO Dynamics is an IT support and managed services company headquartered at 3030 Lincoln Avenue #211, Coquitlam, BC V3B 6B4. We serve businesses across Greater Vancouver and the Fraser Valley with business IT support, managed IT, Microsoft 365, network engineering, enterprise wireless, cloud systems, backups, cybersecurity and technology projects. Our team includes engineers with Cisco, Fortinet, Microsoft, and AWS certifications. Our engineers bring experience supporting 300+ organizations across their careers. Rated 5.0 on Google. For urgent IT help, call (778) 775-4535 or email info@nyrodynamics.com.