Applicability Note
This article applies when a yacht is choosing, replacing, or reviewing its firewall platform.
On many yachts, the firewall is also responsible for VLAN routing, DNS forwarding, DHCP, VPN, web filtering, WAN failover, logging, and vendor remote access. The correct platform depends less on brand preference and more on the yacht's operating model, support provider, WAN design, cyber requirements, and onboard technical capability.
This article is not a full design standard. For classed vessels, newbuilds, refits, or systems connected to bridge, engineering, security, or other OT environments, confirm the applicable flag, class, owner, management-company, and cyber-governance requirements.
What You Should Learn
- Compare FortiGate, Palo Alto, and KerioControl in a yacht context.
- Choose a firewall based on supportability, not only features.
- Decide whether the firewall should own DNS, DHCP, VPN, logging, and WAN failover.
- Identify the minimum handover information required before accepting a firewall replacement.
- Understand why simple networks and complex networks need different firewall platforms.
Why The Firewall Matters Onboard
On a yacht, the firewall is usually the control point between the outside world and the onboard network. It may sit between Starlink, VSAT, 5G/LTE, marina Wi-Fi, guest networks, crew networks, owner office, AV, CCTV, and technical systems. If it is badly designed or poorly documented, the yacht may lose internet resilience, vendor support access, logging, segmentation, or cyber visibility.
IMO maritime cyber-risk guidance defines maritime cyber risk around threats to computer-based systems that may result in operational, safety, or security failures. NIST firewall guidance treats firewalls as controls between networks or hosts with different security postures and recommends formal firewall policy, selection, configuration, testing, deployment, and management.
For yachts with bridge-adjacent, engineering, monitoring, access-control, CCTV, or automation networks, the firewall decision should also consider OT risk. NIST OT guidance highlights that OT systems have specific performance, reliability, and safety requirements. Firewall rules and remote access should not be changed casually around operational systems.
Platform Selection Summary
- FortiGate
- Mid-size to large yachts needing practical WAN handling, VLAN routing, VPN, filtering, logging, and broad supportability. Rules, objects, VPNs, and temporary access can become messy without review.
- Palo Alto
- Larger yachts, fleets, owner-office-connected vessels, or managed-security environments. Strong application, user, content, and central-management model, but it needs trained PAN-OS support and clear
- KerioControl
- Smaller or simpler yachts needing manageable firewall, VPN, filtering, and bandwidth control. Easier to administer, but should not be stretched into complex OT, owner-office, or formal cyber-governanc
The best yacht firewall is the one the yacht can operate safely during a guest trip, yard period, connectivity failure, or urgent vendor-support call.
FortiGate
FortiGate is often the practical middle ground for yacht networks. A FortiGate 100F or 101F-class firewall is a common reference point for a mid-size yacht with multiple VLANs, several WAN paths, VPN requirements, and guest/crew/owner network separation.
Fortinet documentation describes the FortiGate 100F and 101F platform architecture, including multiple copper, SFP, and 10G SFP+ interfaces. Fortinet also positions FortiGate/FortiOS as a next-generation firewall platform with security, VPN, routing, filtering, and secure SD-WAN capabilities.
FortiGate is a good fit when the yacht needs:
- Multiple WAN links
- Strong fit.
- Starlink, VSAT, 5G, or marina Wi-Fi handling
- Strong fit when configured properly.
- Guest, crew, owner, AV, CCTV, and technical VLANs
- Strong fit.
- Site-to-site or vendor VPN
- Strong fit.
- Web filtering and security profiles
- Strong fit with correct licensing.
- Central logging
- Strong fit with FortiAnalyzer or syslog.
- Wider Fortinet stack
- Strong fit with FortiSwitch, FortiAP, FortiAnalyzer, or FortiManager.
The watch point is discipline. FortiGate rules can grow over time, old vendor VPNs can remain enabled, and unused firewall objects can sit in the configuration for years. If a yacht uses FortiGate, the support team should maintain a rule register, VPN register, config backup, firmware plan, and logging destination.
Good yacht fit: a managed yacht network with guest, crew, owner, AV, CCTV, and technical VLANs where capability and practical supportability both matter.
Palo Alto
Palo Alto Networks is the more formal security-operations option. It is well suited to larger yachts, fleets, owner-office-connected vessels, and networks managed by a professional cyber-security provider.
The PA-400 Series is positioned by Palo Alto Networks for small organizations and branch offices, and the PA-400 hardware reference describes visibility and control across applications, users, and content. PAN-OS is built around Palo Alto technologies such as App-ID, Content-ID, Device-ID, and User-ID.
Palo Alto is a good fit when the yacht needs:
- Strong application control
- Strong fit.
- Owner-office or fleet security alignment
- Strong fit.
- Formal security policy and logging
- Strong fit.
- Central management
- Strong fit with Panorama.
- Security-provider operation
- Strong fit.
- Casual onboard administration
- Weaker fit unless crew are trained.
The risk is support dependency. PAN-OS policy is powerful, but it is not something an untrained crew member should improvise on during an outage. If only one shore-side engineer can make changes, the yacht may be exposed during travel, charter, refit, or time-zone mismatch.
A Palo Alto design should include documented zones, policy ownership, NAT rules, VPN users, GlobalProtect configuration if used, logging, commit/rollback process, Panorama ownership, and emergency support contacts.
Good yacht fit: a larger yacht, fleet, or owner-office-connected vessel with trained security support and formal change control.
KerioControl
KerioControl is simpler and can be the correct answer for smaller yachts. GFI describes KerioControl as a unified threat management firewall with intrusion prevention, content filtering, reporting, bandwidth management, and VPN. GFI support documentation also covers single-link, multiple-link failover, and load-balancing internet modes.
KerioControl is a good fit when the yacht needs:
- Guest and crew internet
- Good fit.
- Basic office network
- Good fit.
- Simple VPN
- Good fit.
- Web filtering
- Good fit.
- Bandwidth rules
- Good fit.
- Multi-link internet handling
- Good fit for simpler designs.
- Complex OT separation
- Poor fit.
- High-value owner-office security
- Usually poor fit.
- Formal security operations
- Usually poor fit.
The limit is complexity. KerioControl should not be forced into a network that needs mature OT separation, detailed security logging, complex vendor access, multi-provider cyber governance, or tight owner-office controls.
Good yacht fit: a smaller or simpler vessel where the network is understood and the support team values clarity over depth.
DNS, DHCP, And VPN Ownership
Before choosing a firewall, decide what it will own.
- DNS
- Upstream resolvers, filtering service, split DNS, local overrides, and failover behaviour.
- DHCP
- Scopes, reservations, lease times, excluded ranges, and VLAN relationship.
- VPN
- Users, vendors, tunnels, MFA, expiry dates, reachable subnets, and approval owner.
- WAN failover
- WAN priority, health checks, routing rules, and traffic steering.
- Logging
- Local logs, remote syslog, FortiAnalyzer, Panorama, and retention period.
- Firewall rules
- Rule purpose, owner, approval date, review date, source, destination, and service.
- Licences
- Security subscriptions, support contracts, expiry dates, and renewal owner.
This is where many yacht networks fail. The firewall may be technically capable, but nobody knows why a rule exists, which vendor owns a VPN, or whether a DHCP scope was temporary.
A firewall replacement should not proceed without first exporting the old configuration and identifying DNS, DHCP, VLAN, VPN, WAN, logging, and rule ownership.
Minimum Handover Pack
Before accepting a new or replacement firewall, the yacht should receive a handover pack.
- Network diagram
- WANs, firewall interfaces, switches, VLANs, Wi-Fi, servers, and key systems.
- VLAN matrix
- VLAN names, subnets, gateways, DHCP ownership, and allowed inter-VLAN traffic.
- Firewall rule register
- Rule purpose, owner, source, destination, service, and expiry or review date.
- VPN register
- Users, vendors, tunnels, MFA status, approval owner, and reachable subnets.
- DNS/DHCP register
- Scopes, reservations, upstream DNS, and local overrides.
- Admin access list
- Admin accounts, MFA status, and emergency account process.
- Logging plan
- Where logs are stored and how long they are retained.
- Backup process
- Config export method, storage location, and restore procedure.
- Firmware plan
- Current version, target version, update window, and rollback process.
- Licence record
- Subscription and support expiry dates.
- Support contacts
- Onboard owner, shore provider, SatCom provider, and cyber specialist.
This pack matters more than the logo on the firewall.
Training Requirements
The onboard IT admin does not need to be a firewall architect, but they do need enough knowledge to avoid damage and support safe operations.
- FortiGate
- Policies, objects, VLAN interfaces, SD-WAN basics, VPN, firmware updates, backup/restore, and FortiAnalyzer or syslog logs.
- Palo Alto
- Zones, security policy, NAT, objects, App-ID concepts, GlobalProtect if used, commit process, logs, and Panorama escalation.
- KerioControl
- Traffic rules, interfaces, VPN, content filtering, bandwidth controls, backups, updates, and user management.
For all three platforms, the onboard admin should be able to:
- Export a configuration backup.
- Read recent logs.
- Disable a vendor VPN.
- Identify DHCP scopes.
- Confirm DNS forwarding.
- Explain which VLANs can communicate.
- Contact the correct support provider.
- Restore service from an agreed backup or escalation plan.
Practical Yacht Scenario
A yacht replaces an old firewall before the season. The existing firewall handles Starlink, VSAT, guest Wi-Fi, owner office, AV, CCTV, and engineering monitoring. Several vendor VPN objects remain from the last yard period.
The correct first step is not buying new hardware. The correct first step is to export the existing configuration and document:
- WAN
- Which links exist and how do they fail over?
- VLANs
- Which networks are routed by the firewall?
- DNS
- Who provides DNS and filtering?
- DHCP
- Which scopes and reservations exist?
- VPN
- Which vendors still have access?
- Rules
- Which rules are current, temporary, or unknown?
- Logs
- Where are logs stored and who reviews them?
- Backup
- Can the firewall config be restored?
After that review, FortiGate may be the best practical platform, Palo Alto may be justified for a security-managed vessel, or KerioControl may be sufficient for a simple yacht.
Firewall Selection Check
Before choosing the platform, answer these questions:
- Who will make firewall changes?
- Determines whether the platform is supportable.
- Who approves vendor VPNs?
- Prevents permanent unmanaged access.
- Where are logs stored?
- Supports troubleshooting and incident review.
- Can the config be restored?
- Reduces outage risk.
- Who owns DNS and DHCP?
- Prevents hidden network dependencies.
- Which VLANs are allowed to talk?
- Confirms segmentation.
- Which licences expire this year?
- Prevents sudden loss of security services.
- What happens if shore support is asleep?
- Tests the real operating model.