Engagement story
- Customer
- Multibillion-dollar telecommunications software provider
- Industry
- Telecommunications software
- Technologies
- Cisco Secure Firewall 3120 · Cisco ASA 5555 · Cisco Firepower 2130 · Cisco Secure Firewall Management Center · Snort 3 IPS · LACP EtherChannel · ACL hit-count analysis
The problem
The customer was running an aging Cisco ASA estate and needed two things before committing to new hardware: a validated design for Cisco Secure Firewall 3120, and a migration plan precise enough to execute without guesswork. One constraint shaped every deliverable — the customer's team would perform all configuration work themselves, and BTA had no device access to validate live settings, so the documentation had to carry the whole engagement. Underneath the hardware question sat a policy question nobody had answered: the rulebase had grown across years of change requests, and nothing told the team which rules were still carrying traffic and which were residue.
How BTA delivered
BTA ran the engagement as a mentoring engagement through the Cisco DSI program — not a report to file, but a design and a procedure the customer's team could execute and then own. The design workshop closed in a single session, ahead of schedule, covering native active/standby HA, LACP EtherChannel, IPS integration, and ACL optimization on the Cisco Secure Firewall 3120 platform. When the customer asked for an expanded active/active clustering analysis mid-engagement, BTA turned it around before the next follow-up call. The migration MOP addressed the traps that stall real change windows, including management center version sequencing, and BTA walked the team through every supported method for applying IPS policy rather than picking one and moving on. A full ACL analysis of all 2,163 rules ran alongside the design work, delivered as a working spreadsheet the team could filter and act on.
Outcomes in production
In roughly four weeks of fully remote delivery, the customer received a complete design recommendation, a migration MOP their own engineers could execute, and an ACL analysis that reframed the project: of 2,163 firewall rules, 1,932 carried a zero hit count — 89% of the rulebase doing no work, and left alone, every one of those rules would have been copied forward onto new hardware along with the audit burden and attack surface that comes with them. The migration stopped being a hardware refresh and became the moment to rebuild policy on evidence: 231 rules carrying real traffic, and a documented case for retiring the rest. Every milestone was met remotely, with no travel and no scope creep beyond the agreed deliverables. The engagement also mapped what comes next — migration execution support during the change window, post-migration policy rationalization, and workload segmentation across the customer's multi-tier firewall architecture.