Network Security

UTM & Firewall Security for
Hotels, Campuses and Offices

Firewall policy, application and content filtering, intrusion prevention, VPN and multi-ISP failover on one managed device - installed and supported by iberry from Mohali, across North India.

The problem a UTM actually solves

A hotel, a college or an office with public WiFi is running a small public ISP, and it carries the same three obligations: keep the guests apart from your own systems, control what the network may be used for, and be able to say afterwards who did what. A router handed over by the broadband provider addresses none of them. It hands out addresses and gets out of the way.

Unified threat management means putting the parts that do address them into one managed device: a stateful firewall that separates the guest network from the PMS server and the cameras, application and category filtering that decides what the connection may be used for, intrusion prevention on anything you expose, and records that survive the guest’s departure. On an iberry site that device is the same one running the hotspot and captive portal, which is what makes the isolation real rather than nominal.

None of this is exotic, and it is not expensive relative to what it protects. It is simply not what arrives in the box from the ISP.

What the iberry security stack includes

Deployed on standard MikroTik RouterOS hardware and managed centrally, with the higher tiers adding gateway antivirus and word and URL filtering.

🧱

Stateful firewall policy

Rules that decide what may cross between the internet, your office LAN, the guest network and the management network. The guest side is isolated, so a device on the public WiFi cannot reach your PMS server, your cameras or the back-office machines.

🔎

Layer 7 application filtering

Application-aware rules that can stop traffic the port number alone will not reveal - BitTorrent and similar clients being the usual reason a property's bandwidth disappears overnight.

🛡️

Intrusion detection and prevention

Real-time inspection for known attack patterns against anything you expose, with the option to drop the source rather than only log it.

🚫

Content and URL filtering

Category-based blocking - adult, gambling, malware hosts - plus word and URL filters on the higher tiers. On a guest network this is usually a licensing and liability requirement rather than a preference.

🧬

Gateway antivirus

Scanning at the gateway on the Standard tier, so a compromised guest laptop is dealt with before it reaches the rest of the property.

🔒

VPN, site-to-site and remote user

Encrypted WireGuard tunnels between properties and for staff working away from the building, so a group's sites and its people share one private network instead of exposing services to the internet.

🔄

Multi-ISP failover and load balancing

Two or more internet links, with traffic moved to the surviving one automatically when a link dies and moved back when it returns. Recursive routing with gateway checks does the switching; PCC spreads load when both are healthy.

📓

Logging and accounting

Who connected, when, from which device, and how much they used, retained and available to you. A public-facing network in India is expected to be able to answer that question long after the guest has left.

Why we build it on RouterOS rather than an appliance

A proprietary UTM appliance sets two prices: the one you pay now, and the one you pay when it reaches end of life, when the throughput licence needs raising, or when the subscription that keeps the filtering current lapses. The hardware and the software are the same purchase, so you cannot change one without the other.

iberry deploys the same capabilities on standard MikroTik RouterOS equipment. The hardware is commodity and replaceable, the configuration is ours and portable, and the management, policy and reporting run in the iberry cloud rather than on a box in your server room that somebody has to patch. If you later move the site, or grow out of the device, the platform moves with you.

The trade-off is honest and worth stating: this is a managed service, not a product you administer yourself. If your requirement is an in-house team holding the console, say so and we will tell you whether we are the right fit.

Frequently asked questions

What is a UTM firewall, and how is it different from the router my ISP gave me?

UTM stands for unified threat management: one device doing firewalling, application and content filtering, intrusion prevention, antivirus and VPN together, rather than a separate box for each. An ISP-supplied router does none of those - it gives you an address and a NAT table. The practical difference on a property is that a UTM can separate the guest network from your own, decide what traffic is allowed, and tell you afterwards what happened.

Which hardware does iberry deploy it on?

Standard MikroTik RouterOS equipment, sized to the property - the same range the published Lite, Medium and Standard plans are built around. It is deliberately not a proprietary appliance: the hardware is widely available, and replacing or upgrading it does not mean renegotiating a licence.

Can the firewall and the guest WiFi be the same system?

Yes, and on most of our sites they are. The same RouterOS device runs the hotspot and captive portal, the per-guest speed and data limits and the firewall policy, and all of it is managed centrally from the iberry cloud. That is why guest isolation actually holds - the rules and the login system are not two vendors' products bolted together.

Do you do the installation, or just supply the box?

Both, and we prefer to do the installation. Our engineers are based at TDI Business Centre, Sector 118, Mohali, and cover Chandigarh, Mohali, Panchkula, Zirakpur and Kharar on site, with the rest of North India by arrangement. Day to day the device is managed remotely over an encrypted tunnel.

What does it cost?

The published plans are ₹30,000 one-time for a small site, ₹50,000 for a medium one and ₹99,000 for large and five-star properties, each with ₹12,000 yearly maintenance. What changes the figure is the hardware the site needs, not a per-seat licence. Full detail is on the pricing page.

We already have a firewall. Can you take it over?

If it is RouterOS, usually yes - we can adopt an existing router rather than replace it, which is how several of our sites started. If it is another vendor's appliance we will tell you plainly whether it is worth keeping in place alongside the WiFi platform or replacing.

Want the guest network off your own network?

Tell us what is installed today and what the property has to protect, and we will come and look at it. See also the supported hardware and plans, hotspot billing and our tricity service area.

Talk to an Engineer