Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

When an edge device cannot be patched promptly, reduce the paths an attacker can use to reach it, apply the manufacturer’s mitigation for the specific flaw, and monitor the device and its network. These measures—often called virtual patching—are temporary risk controls, not a firmware fix. There is no single standardized virtual-patching technique: the right controls depend on the device, vulnerability, network design, and operational and safety requirements.

1. Identify the affected device and its exposure

Start with an accurate inventory of edge devices, models, firmware versions, network locations, and support status. Compare it with the product’s current security advisories to determine which assets are affected and whether the vendor has issued a patch or interim mitigation. CISA’s Enhanced Visibility and Hardening Guidance for Communications Infrastructure calls for maintaining device and firmware inventories and monitoring vendor patch announcements.

  • Check whether the device is reachable from the public internet, business networks, remote-access systems, or other less-trusted segments.
  • Identify the services and protocols it must use, who administers it, and which management paths are enabled.
  • Record whether the vendor still supports the device and firmware. CISA’s Internet Exposure Reduction Guidance, published June 4, 2025, recommends replacing unsupported software and devices.

This inventory determines where a control can be applied and what legitimate operations it must preserve.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

2. Apply the manufacturer’s mitigation for the specific flaw

Use the vendor’s advisory or written mitigation from the manufacturer or reseller for the affected product and vulnerability. CISA and partner agencies state in Mitigating Log4Shell and Other Log4j-Related Vulnerabilities: “If patches cannot be applied, mitigations provided by the product’s manufacturer or reseller should be deployed.” Although that guidance addresses Log4j-related vulnerabilities, the advice illustrates why an interim measure should be tied to the actual product and flaw.

#1 Best Overall
Netgate 1100 pfSense+ Security Gateway - Firewall, Router, VPN
  • BUSINESS READY - pfSense+ software updates included for product lifetime. Netgate TAC Lite technical support included. One year hardware warranty included.
  • COMPLETE - Pre-loaded with pfSense+ software to get up and running fast. Simply unbox it and start customizing for your secure edge networking needs. Free help with setup from our expert Technical Assistance Center (TAC) available 24/7/365.
  • POWERFUL - A dual core ARM Cortex-A53 1.2 GHz delivers near gigabit routing of common home iPerf3 traffic and in excess of 650 Mbps of firewall throughput.
  • COMPACT - Low power draw, a compact form factor, and silent operation allow it to run unnoticed when placed on a desktop, wall, or rack.
  • FLEXIBLE - Three (3) 1 GbE switched (WAN/LAN/OPT) ports allow you to configure three separate 1 GbE switched ports for upto a gigabit of bi-directional traffic.

Do not assume a generic firewall rule, network filter, or intrusion-prevention signature addresses every firmware vulnerability. Confirm the recommended control’s scope, prerequisites, side effects, and any required device configuration with the vendor. If no specific mitigation is available, use exposure-reduction controls chosen for the device and environment, and keep the unresolved vulnerability visible in risk decisions.

A device-specific example, not a universal recipe

A 2017 CISA advisory for Schneider Electric Modicon PLCs described compensating controls for a specific issue involving insufficiently protected credentials. The advisory included limiting local-network traffic with managed switches, avoiding Wi-Fi where possible, not granting access to unknown computers, and using maintained secure remote access when necessary. It also recommended minimizing exposure and isolating control networks. Those measures were tied to the products and vulnerability in that advisory; they should not be copied unchanged as a prescription for other devices.

Rank #2
SonicWall TZ270 TradeUp | 3YR Essential Edition | TZ270 Gen7 Firewall with 3 Year EPSS and 1 Year Cloud Secure Edge | Compact SMB Appliance with Threat Protection and SD-WAN (03-SSC-2997)
  • SonicWall TZ270 with 3 Year EPSS and 1 Year Cloud Secure Edge - TradeUp (03-SSC-2997) - Entry-level Gen 7 firewall for small businesses, lean branch offices, and retail environments that need affordable enterprise-grade cybersecurity with gigabit performance and easy deployment.
  • Essential Protection Service Suite (EPSS) delivers comprehensive firewall security with Gateway Anti-Virus, Intrusion Prevention, Application Control, Content Filtering, and 24×7 Support with firmware updates. Provides full-spectrum defense against known and emerging threats while simplifying renewals and licensing for small and mid-sized businesses.
  • Defends against ransomware, malware, intrusions, and encrypted threats using Reassembly-Free Deep Packet Inspection (RFDPI), Real-Time Deep Memory Inspection (RTDMI), and Capture ATP cloud sandboxing.
  • Flexible connectivity with eight Gigabit Ethernet interfaces, USB ports, and Zero-Touch deployment to simplify remote rollout and reduce IT workload.
  • The SonicWall Trade Up program provides a direct path for existing SonicWall customers to exchange an eligible device for a new Gen 7 firewall. By supplying the serial number of a current unit, organizations can transition to the latest platform and select the subscription level that best fits their needs, from Essential to Advanced to Managed Protection Service Suites. This approach ensures customers benefit from updated performance, expanded features, and ongoing security coverage.

3. Reduce the paths to the device

Choose controls based on the asset’s required communications, architecture, safety, and availability needs. CISA’s OT/ICS guidance emphasizes that network architecture and segmentation affect risk, and that defensive changes require impact analysis and risk assessment.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Limit exposure. Remove unnecessary internet reachability and restrict access from network segments that do not need to communicate with the device. CISA’s 2025 Internet Exposure Reduction Guidance also recommends monitored jump hosts for access and monitoring ingress and egress traffic.
  • Separate control and business networks. Where the architecture supports it, place control-system networks and remote devices behind firewalls and isolate them from business networks, following the applicable vendor guidance.
  • Restrict management access. Permit administration only through trusted paths and authorized accounts. CISA’s communications-infrastructure guidance describes default-deny access-control lists (ACLs) and a physically separate out-of-band management network as protective approaches.
  • Apply controls upstream when needed. If a device cannot enforce ACLs, network controls may be possible on an upstream switch or other network boundary. A 2025 CISA advisory describes placing devices that lack ACL capability on a separate management VLAN.
  • Monitor the controls and the asset. Review network traffic, device logs, configurations, and exposure for unexpected activity or changes. Repeat assessments as devices, connections, and operating requirements change.

These measures address different paths and are not interchangeable. For each one, determine which protocols and connections it affects, how legitimate operations will be preserved, and how staff will detect a failed or bypassed control.

Rank #3
SonicWall TZ370 TradeUp | 3YR Essential Edition | TZ370 Gen7 Firewall with 3 Year EPSS and 1 Year Cloud Secure Edge | Advanced SMB Appliance with SD-WAN and Threat Defense (03-SSC-3005)
  • SonicWall TZ370 with 3 Year EPSS and 1 Year Cloud Secure Edge - TradeUp (03-SSC-3005) - Designed for growing SMBs that need more throughput and scalability, delivering multi-gigabit firewall performance with best-in-class price to performance.
  • Essential Protection Service Suite (EPSS) delivers comprehensive firewall security with Gateway Anti-Virus, Intrusion Prevention, Application Control, Content Filtering, and 24×7 Support with firmware updates. Provides full-spectrum defense against known and emerging threats while simplifying renewals and licensing for small and mid-sized businesses.
  • Protects against encrypted malware and intrusions using DPI-SSL inspection, IPS, anti-malware, and Capture ATP sandboxing with RTDMI detection.
  • Secure SD-WAN intelligently steers traffic across links to reduce MPLS costs and improve cloud application performance for branch users.
  • The SonicWall Trade Up program provides a direct path for existing SonicWall customers to exchange an eligible device for a new Gen 7 firewall. By supplying the serial number of a current unit, organizations can transition to the latest platform and select the subscription level that best fits their needs, from Essential to Advanced to Managed Protection Service Suites. This approach ensures customers benefit from updated performance, expanded features, and ongoing security coverage.

4. Track the residual risk and reassess

Document what remains reachable, what the interim controls cover, and what they do not cover. A measure that blocks one route may leave another open; connected devices and remote-access solutions can also introduce vulnerabilities. Assign an owner to review the device’s exposure, monitoring, and mitigation status as the network or threat conditions change.

Before changing network access or device behavior, assess the effects on safety, availability, and essential operations with the relevant engineering and operations teams. CISA advises risk-informed decisions for OT/ICS environments because a protective change can itself have operational consequences.

Rank #4
Juniper SSG-5-SB 128MB Security Services Gateway
  • Complete set of Unified Threat Management (UTM) security features
  • Centralized, policy-based management minimizes the chance of overlooking security holes by simplifying rollout and network-wide updates
  • Virtualization technologies make it easy for administrators to divide the network into secure segments for additional protection
  • Various high availability (HA) options offer the best redundant capabilties for any given network
  • Rapid-deployment features, including Auto Connect VPN and Dynamic VPN services, help minimize the administrative burden associated with widespread IPsec deployments
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

5. Test and install the vendor’s firmware fix

Track the vendor’s remediation and assess its operational impact. CISA’s joint guidance recommends testing updates in a development environment that reflects production and applying patches through a risk-informed process as operationally feasible.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Obtain the update and installation instructions from the device vendor, and confirm which product and firmware versions they cover.
  2. Test the update in a representative environment. Check required communications, control behavior, integrations, and recovery procedures before scheduling production deployment.
  3. Deploy the update when the operational risk is acceptable, using the vendor’s procedure and the organization’s change controls.
  4. Verify the installed version and update status using the device’s vendor-specific method. Keep interim controls and monitoring under review until remediation is confirmed.

There is no universal verification method for every edge device; use the procedure applicable to the specific model and firmware.

Best Value
SonicWall TZ370 TradeUp | 3YR Advanced Edition | TZ370 Gen7 Firewall with 3 Year APSS and 1 Year Cloud Secure Edge | Advanced SMB Appliance with SD-WAN and Threat Defense (03-SSC-3004)
  • SonicWall TZ370 with 3 Year APSS and 1 Year Cloud Secure Edge - TradeUp (03-SSC-3004) - Designed for growing SMBs that need more throughput and scalability, delivering multi-gigabit firewall performance with best-in-class price to performance.
  • Advanced Protection Service Suite (APSS) offers next-generation security combining Gateway AV, IPS, Application Control, Content Filtering, 24×7 Support, Capture ATP sandboxing, and RTDMI. Protects against ransomware, zero-day exploits, and encrypted attacks with multi-layered threat prevention and scalable, enterprise-grade performance.
  • Protects against encrypted malware and intrusions using DPI-SSL inspection, IPS, anti-malware, and Capture ATP sandboxing with RTDMI detection.
  • Secure SD-WAN intelligently steers traffic across links to reduce MPLS costs and improve cloud application performance for branch users.
  • The SonicWall Trade Up program provides a direct path for existing SonicWall customers to exchange an eligible device for a new Gen 7 firewall. By supplying the serial number of a current unit, organizations can transition to the latest platform and select the subscription level that best fits their needs, from Essential to Advanced to Managed Protection Service Suites. This approach ensures customers benefit from updated performance, expanded features, and ongoing security coverage.

How to evaluate a proposed interim control

Before approving a control, ask:

  • Does the vendor advisory support it for this device and vulnerability?
  • Which network paths, services, or protocols will it actually constrain?
  • Could it disrupt safety functions, availability, or required operations?
  • Can the team observe whether it is operating, and detect failure or bypass?
  • What effort is required to deploy and maintain it?
  • How will it be removed or revised after the firmware remediation is installed?

Use the answers to make the remaining risk and operational trade-offs explicit. CISA’s ICS Recommended Practices also provides an index of patch-management and defense-in-depth materials for industrial control environments.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.