Solutions
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" fill="none"> <path d="M21.25 12C21.25 13.2426 20.2426 14.25 19 14.25C17.7574 14.25 16.75 13.2426 16.75 12C16.75 10.7574 17.7574 9.75 19 9.75C20.2426 9.75 21.25 10.7574 21.25 12Z" stroke="black" stroke-width="1.5"/><path d="M7.25 12C7.25 13.2426 6.24264 14.25 5 14.25C3.75736 14.25 2.75 13.2426 2.75 12C2.75 10.7574 3.75736 9.75 5 9.75C6.24264 9.75 7.25 10.7574 7.25 12Z" stroke="black" stroke-width="1.5"/><path d="M14.3752 16.1143C15.4512 15.4931 16.827 15.8617 17.4482 16.9377C18.0694 18.0137 17.7008 19.3895 16.6248 20.0107C15.5488 20.6319 14.173 20.2633 13.5518 19.1873C12.9306 18.1113 13.2992 16.7355 14.3752 16.1143Z" stroke="black" stroke-width="1.5"/><path d="M7.37519 3.98927C8.45117 3.36805 9.82701 3.73671 10.4482 4.81269C11.0694 5.88867 10.7008 7.26451 9.62481 7.88573C8.54883 8.50695 7.17298 8.13829 6.55177 7.06231C5.93055 5.98633 6.29921 4.61048 7.37519 3.98927Z" stroke="black" stroke-width="1.5"/><path d="M7.37519 20.0107C6.29921 19.3895 5.93055 18.0137 6.55177 16.9377C7.17298 15.8617 8.54883 15.4931 9.62481 16.1143C10.7008 16.7355 11.0694 18.1113 10.4482 19.1873C9.82701 20.2633 8.45117 20.6319 7.37519 20.0107Z" stroke="black" stroke-width="1.5"/><path d="M14.3752 7.88573C13.2992 7.26451 12.9306 5.88867 13.5518 4.81269C14.173 3.73671 15.5488 3.36805 16.6248 3.98927C17.7008 4.61048 18.0694 5.98633 17.4482 7.06231C16.827 8.13829 15.4512 8.50695 14.3752 7.88573Z" stroke="black" stroke-width="1.5"/> </svg>

Modern Work

Modern workplaces and collaboration.

Effective solutions
We solve the IT challenges that most hinder Swiss SMEs. From Modern Work and Cyber Security to Cloud Migration.
Discover all solutions
Services
Craftsmanship Excellence
We support you from strategy consulting to seamless 24/7 operations. Professional, proactive, and individually tailored to your infrastructure.
Compare Service Models
About
Our story
100 years of experience. Your partner for innovation since 1925.
Network

Managed Network Services: Secure, High-Performance Networks for Businesses

Secure, high-performance networks for every location and remote workplace. So your IT stays in control without having to intervene manually with every change.

Two smiling men at a glass wall covered with notes in a bright, modern office
Challenges

Do you really know which devices are active on your network right now?

Your firewall rules are a patchwork

Grown over years, never cleaned up: nobody knows exactly which rules exist and why, or which have long been obsolete.

01

Remote access means VPN frustration

Employees working from home struggle with slow VPN connections, while your IT team battles tickets and configuration overhead.

02

No overview of who is on the network

Printers, laptops, IoT devices, guest access: all in the same segment, without segmentation and without access control.

03

The Root Cause

Grown piece by piece. Never planned as a whole.

Your network works. Somehow. But when every firewall change is a risk, remote access runs through outdated VPN tunnels and nobody knows which devices are currently on the network, your network turns from a foundation into a weak point. And every day without segmentation is a day an attacker can move laterally unhindered.

Mitarbeiter konzentriert am Laptop im Büro, Kollege mit Headset im Hintergrund
Vorher & nachher

And this is what your network looks like when it is done right.

Before & After

And this is what your network looks like when it is done right.

Without Baggenstos

With

Firewall rules as a patchwork

Clear, centrally managed security policies with FortiGate

Consistent firewall rules across all locations. Transparent, documented and traceable at any time.

VPN frustration with remote access

Zero Trust Network Access replaces your traditional VPN

Employees access applications securely, without a VPN client and without performance loss. Only verified people, only authorised apps.

No overview of devices

Network Access Control: only authorised devices on the network

Every device is identified and segmented before it gains access. Unauthorised devices are automatically isolated.

Wi-Fi with dead zones

Comprehensive enterprise Wi-Fi with central management

FortiAP access points for seamless coverage. Uniformly configured, centrally monitored, scalable for new floors or locations.

Every change requires manual intervention

Central management for firewall, switches and access points

One console for your entire network. Roll out changes, enforce policies and detect anomalies without having to be on site.

Mit

Clear, centrally managed security policies with FortiGate

Consistent firewall rules across all locations. Transparent, documented and traceable at any time.

Zero Trust Network Access replaces your traditional VPN

Employees access applications securely, without a VPN client and without performance loss. Only verified people, only authorised apps.

Network Access Control: only authorised devices on the network

Every device is identified and segmented before it gains access. Unauthorised devices are automatically isolated.

Comprehensive enterprise Wi-Fi with central management

FortiAP access points for seamless coverage. Uniformly configured, centrally monitored, scalable for new floors or locations.

Central management for firewall, switches and access points

One console for your entire network. Roll out changes, enforce policies and detect anomalies without having to be on site.

Your Benefits

What this means for your everyday work

Zwei Mitarbeiter betrachten gemeinsam einen Laptop vor einer beschriebenen Glaswand im Büro

Secure access, everywhere

Your employees access company resources securely from any location. Without a VPN client, without performance losses. Zero Trust ensures that only the right person accesses the right application.

Full transparency

You can see at any time which devices are active on your network, who is accessing it and where anomalies occur. No more blind spots, no nasty surprises at the next audit.

Less complexity

Firewall, switches, access points and remote access from a single source, centrally managed. Instead of maintaining five different management tools, you control everything through one platform.

Protection from within

Network segmentation prevents a compromised device from moving freely across the network. Even if an endpoint is affected, the damage stays contained.

Scale with future certainty

New location, new floor, 50 additional employees? Your network infrastructure grows with you, without you having to redesign the architecture every time.

Leistungen

And this is what your network looks like when it is done right.

<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" fill="none"> <path d="M20.25 5.5L12 2.75L3.75 5.5V11.9123C3.75 16.8848 8 19.25 12 21.4079C16 19.25 20.25 16.8848 20.25 11.9123V5.5Z" stroke="black" stroke-width="1.5" stroke-linecap="square" stroke-linejoin="round"/> </svg>

Fortinet Firewall (FortiGate)

Next-Generation Firewalls with Intrusion Prevention, Application Control, and SSL Inspection. Your first line of defense, centrally managed across all locations.

<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" fill="none"> <circle cx="9.25" cy="5.75" r="3" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/><path d="M9.25 9V17.5C9.25 19.5711 10.9289 21.25 13 21.25C15.0711 21.25 16.75 19.5711 16.75 17.5V12L13.75 15" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/> </svg>

LAN Infrastructure (FortiSwitch)

Managed switches that work seamlessly with your firewall. Port-based segmentation, PoE for access points, and central configuration without separate switch management.

<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" fill="none"> <path d="M21 7.82177C15.751 3.72477 8.249 3.72477 3 7.82177M6.75098 13.3144C9.81298 10.9264 14.188 10.9264 17.25 13.3144" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/><path d="M12 18.25C12.4142 18.25 12.75 18.5858 12.75 19C12.75 19.4142 12.4142 19.75 12 19.75C11.5858 19.75 11.25 19.4142 11.25 19C11.25 18.5858 11.5858 18.25 12 18.25Z" fill="black" stroke="black" stroke-width="0.5" stroke-linecap="round" stroke-linejoin="round"/> </svg>

Enterprise WLAN (FortiAP)

Professional Access Points for seamless coverage in offices, warehouses, and production facilities. Automatic channel optimization and consistent policies for employees and guests.

<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" fill="none"> <path d="M8.25 3.75H3.75V8.25" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/><path d="M15.75 3.75H20.25V8.25" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/><path d="M20.25 15.75V20.25H15.75" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/><path d="M8.25 20.25H3.75V15.75" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/><path d="M8.75 9.75H15.25" stroke="black" stroke-width="1.5" stroke-linecap="round"/><path d="M8.75 14.25H13.25" stroke="black" stroke-width="1.5" stroke-linecap="round"/> </svg>

Network Access Control (FortiNAC)

Identification and segmentation of every device on the network. Only authorized endpoints are granted access. Unauthorized devices are automatically moved to a quarantine segment.

<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" fill="none"> <path d="M3.7503 7.81174L8.0031 10.9999L9.0081 9.00495L13.0031 7.99995L14.2452 3.02438M3.7503 7.81174C3.11062 9.06923 2.75 10.4925 2.75 12C2.75 17.1086 6.89137 21.25 12 21.25C17.1086 21.25 21.25 17.1086 21.25 12C21.25 7.66569 18.2689 4.02764 14.2452 3.02438M3.7503 7.81174C5.27837 4.80785 8.39887 2.75 12 2.75C12.7743 2.75 13.5264 2.84514 14.2452 3.02438" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/><path d="M15 17L16 15L13.052 13.019L11.109 12.895L10 14L12 17H15Z" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/> </svg>

Microsoft Global Secure Access (SASE)

Cloud-native access to enterprise applications, without a traditional VPN. Private Access for internal apps, Internet Access for secure browsing, all controlled via Entra ID.

<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" fill="none"> <path d="M4.75 9.75H19.25V21.25H4.75V9.75Z" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/><path d="M12 14V17" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/><path d="M16.25 9.75V7C16.25 4.65279 14.3472 2.75 12 2.75C9.65279 2.75 7.75 4.65279 7.75 7V9.75" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/> </svg>

Zero Trust Network Access (ZTNA)

Access is granted per application and per user, not per network. Identity, device compliance, and location are factored into every access decision.

<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" fill="none"> <path d="M12 16.25V20.25M12 16.25H5L2 12L5 7.75H12V16.25ZM12 3.75H19L22 8L19 12.25H12V3.75Z" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/> </svg>

SD-WAN

Intelligent site connectivity across multiple WAN connections. Automatic routing for optimal performance, integrated into your FortiGate firewall, without additional hardware.

<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" fill="none"> <path d="M2 11.9999C6.82745 2.33329 17.1725 2.3334 22 12C17.1725 21.6666 6.82745 21.6665 2 11.9999Z" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/><path d="M15.25 12C15.25 13.7949 13.7949 15.25 12 15.25C10.2051 15.25 8.75 13.7949 8.75 12C8.75 10.2051 10.2051 8.75 12 8.75C13.7949 8.75 15.25 10.2051 15.25 12Z" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/> </svg>

Network Monitoring & Management

Centralized monitoring of your entire network infrastructure. Anomaly detection, performance dashboards, and automatic alerts, so your IT team sees problems before your employees experience them.

<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" fill="none"> <path d="M20.25 5.5L12 2.75L3.75 5.5V11.9123C3.75 16.8848 8 19.25 12 21.4079C16 19.25 20.25 16.8848 20.25 11.9123V5.5Z" stroke="black" stroke-width="1.5" stroke-linecap="square" stroke-linejoin="round"/> </svg>

Fortinet Firewall (FortiGate)

Next-Generation Firewalls with Intrusion Prevention, Application Control, and SSL Inspection. Your first line of defense, centrally managed across all locations.

<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" fill="none"> <circle cx="9.25" cy="5.75" r="3" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/><path d="M9.25 9V17.5C9.25 19.5711 10.9289 21.25 13 21.25C15.0711 21.25 16.75 19.5711 16.75 17.5V12L13.75 15" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/> </svg>

LAN Infrastructure (FortiSwitch)

Managed switches that work seamlessly with your firewall. Port-based segmentation, PoE for access points, and central configuration without separate switch management.

<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" fill="none"> <path d="M21 7.82177C15.751 3.72477 8.249 3.72477 3 7.82177M6.75098 13.3144C9.81298 10.9264 14.188 10.9264 17.25 13.3144" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/><path d="M12 18.25C12.4142 18.25 12.75 18.5858 12.75 19C12.75 19.4142 12.4142 19.75 12 19.75C11.5858 19.75 11.25 19.4142 11.25 19C11.25 18.5858 11.5858 18.25 12 18.25Z" fill="black" stroke="black" stroke-width="0.5" stroke-linecap="round" stroke-linejoin="round"/> </svg>

Enterprise WLAN (FortiAP)

Professional Access Points for seamless coverage in offices, warehouses, and production facilities. Automatic channel optimization and consistent policies for employees and guests.

<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" fill="none"> <path d="M8.25 3.75H3.75V8.25" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/><path d="M15.75 3.75H20.25V8.25" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/><path d="M20.25 15.75V20.25H15.75" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/><path d="M8.25 20.25H3.75V15.75" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/><path d="M8.75 9.75H15.25" stroke="black" stroke-width="1.5" stroke-linecap="round"/><path d="M8.75 14.25H13.25" stroke="black" stroke-width="1.5" stroke-linecap="round"/> </svg>

Network Access Control (FortiNAC)

Identification and segmentation of every device on the network. Only authorized endpoints are granted access. Unauthorized devices are automatically moved to a quarantine segment.

<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" fill="none"> <path d="M3.7503 7.81174L8.0031 10.9999L9.0081 9.00495L13.0031 7.99995L14.2452 3.02438M3.7503 7.81174C3.11062 9.06923 2.75 10.4925 2.75 12C2.75 17.1086 6.89137 21.25 12 21.25C17.1086 21.25 21.25 17.1086 21.25 12C21.25 7.66569 18.2689 4.02764 14.2452 3.02438M3.7503 7.81174C5.27837 4.80785 8.39887 2.75 12 2.75C12.7743 2.75 13.5264 2.84514 14.2452 3.02438" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/><path d="M15 17L16 15L13.052 13.019L11.109 12.895L10 14L12 17H15Z" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/> </svg>

Microsoft Global Secure Access (SASE)

Cloud-native access to enterprise applications, without a traditional VPN. Private Access for internal apps, Internet Access for secure browsing, all controlled via Entra ID.

<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" fill="none"> <path d="M4.75 9.75H19.25V21.25H4.75V9.75Z" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/><path d="M12 14V17" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/><path d="M16.25 9.75V7C16.25 4.65279 14.3472 2.75 12 2.75C9.65279 2.75 7.75 4.65279 7.75 7V9.75" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/> </svg>

Zero Trust Network Access (ZTNA)

Access is granted per application and per user, not per network. Identity, device compliance, and location are factored into every access decision.

<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" fill="none"> <path d="M12 16.25V20.25M12 16.25H5L2 12L5 7.75H12V16.25ZM12 3.75H19L22 8L19 12.25H12V3.75Z" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/> </svg>

SD-WAN

Intelligent site connectivity across multiple WAN connections. Automatic routing for optimal performance, integrated into your FortiGate firewall, without additional hardware.

<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" fill="none"> <path d="M2 11.9999C6.82745 2.33329 17.1725 2.3334 22 12C17.1725 21.6666 6.82745 21.6665 2 11.9999Z" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/><path d="M15.25 12C15.25 13.7949 13.7949 15.25 12 15.25C10.2051 15.25 8.75 13.7949 8.75 12C8.75 10.2051 10.2051 8.75 12 8.75C13.7949 8.75 15.25 10.2051 15.25 12Z" stroke="black" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/> </svg>

Network Monitoring & Management

Centralized monitoring of your entire network infrastructure. Anomaly detection, performance dashboards, and automatic alerts, so your IT team sees problems before your employees experience them.

Mann und Frau arbeiten lächelnd mit Laptops an einem Holztisch im hellen Büro

Klingt nach dem, was Sie brauchen?

Referenzen

60'000 Benutzer vertrauen uns ihren Arbeitsplatz an. Das hat Gründe.

Hand holding a tablet with the Bossard app in front of a warehouse shelf full of blue parts bins.

50

VMs migrated to Azure

31 countries, one virtual datacenter. Bossard relies on Azure.

Several people in business attire walking through a bright office lobby, the BDO logo in the background.

BDO no longer owns a single server. And that was exactly the plan.

Close-up of a stainless steel industrial filter press with tightly stacked filter plates.

6 months

Until Operation Care operation

350 employees, 8 locations. FILTROX migrates in six months.

Nicolas Schwarzenbach

Nicolas Schwarzenbach

IT Manager, FILTROX AG

With Baggenstos, we are on the right track to advance digitalisation in our everyday business. A particular plus point is that we can now access our applications and data from anywhere and work much more mobile and efficiently. With the new operating model, we have completely new internal possibilities.

Why Baggenstos

Why Baggenstos Should Be Your Partner

60,000+

Microsoft 365 users in the Managed Service Program

1'000+

Cloud projects successfully implemented

Since 1925

100 years of continuity in family ownership

Mehrere Mitarbeiter mit Laptops in einer Besprechung am Konferenztisch im Büro

Holistic consulting

We don't deliver an isolated network project; we integrate LAN, WLAN, firewall and Zero Trust Network Access into your entire IT strategy.

Certified Microsoft excellence

As a Fortinet Expert Partner and Microsoft Solutions Partner, we combine the best of both worlds: classic network security and cloud-native SASE architecture.

Focus on security & compliance

Network security is the first line of defence. We design your infrastructure according to Zero Trust principles, with segmentation, NAC and Global Secure Access.

Guiding the change (change management)

A new network affects every workplace in the company. We plan the rollout so that your day-to-day operations continue without interruption.

FAQ

Frequently asked questions about Network

What does a network project cost?

That depends on your starting point: number of locations, existing hardware, WLAN requirements and the remote access you want. In the free assessment we create a transparent cost overview. Many of our customers save in the long run, because separate VPN infrastructure, outdated firewalls and various management tools are replaced by one integrated platform.

How does SD-WAN work and what advantages does it offer over traditional networks?

SD-WAN bundles internet and MPLS connections intelligently and routes traffic by application priority. Cloud applications such as Microsoft 365 run directly over the fastest connection instead of via central data centres. Locations are provisioned in minutes. You pay predictable operating costs instead of a capital investment.

What do Managed Network Services for businesses include?

We operate your entire network infrastructure: firewall, switches, access points and remote access. Proactive monitoring detects issues before employees notice them. Configuration changes, patches and updates run through us. Service Level Agreements set response times and availability bindingly.

Which network technologies (e.g. Fortinet) does Baggenstos rely on?

Fortinet as an integrated platform: FortiGate for the firewall, FortiSwitch and FortiAP for LAN and WLAN, FortiManager for central management. All components work together as a Security Fabric. For secure cloud access we add Microsoft Global Secure Access. This creates an end-to-end architecture.

How do Managed Network Services ensure security for hybrid working?

With Zero Trust Network Access instead of VPN. Every connection is authorised individually: by identity, device compliance and location. Microsoft Global Secure Access and Fortinet ZTNA verify each access in real time. Employees access applications without a VPN client – more secure than VPN and faster at the same time.

Why should we obtain our firewall as a managed service?

Modern firewalls need 24/7 care: signatures, threat feeds, policy updates and incident analysis. We take over configuration, monitoring and response to incidents with SLA-guaranteed response times. You save the investment in specialised security staff and pay a predictable monthly operating cost.

What happens to our existing network hardware?

During the assessment we analyse which components can continue to be used and where a replacement makes sense. Existing cabling and infrastructure usually remain in place. Outdated firewalls or unmanaged switches are replaced by centrally managed Fortinet components.

Zwei Mitarbeiter im Gespräch am Tisch, einer lächelt im Vordergrund
Jetzt Termin vereinbaren

When shall we bring your network up to date?

Let's work together to make your network infrastructure future-proof.