The customer
An established IT system house and managed service provider with around 20 employees. Its focus is on tax advisory firms: more than 170 clients, each with its own firewall instance, many of them with several branch offices.
The starting position
Over the years, a heterogeneous landscape of open source firewalls had grown up across the client base. Each instance came with its own administration interface and had to be opened, checked and updated individually. Rule set changes, updates and backups were largely manual.
With every additional environment under management, the administrative effort increased in direct proportion. This is the point at which a managed service reaches its limit. Every new client costs the same working time as the one before, without operations becoming any more efficient.
This weighed particularly heavily because tax advisory firms are bound by professional secrecy and their systems must be connected to the DATEV environment permanently and reliably. With this degree of dispersion, a consistent configuration and security standard across all clients could hardly be demonstrated in a reliable way.
The requirement
The provider was looking for a central, multi-client management platform that would make the installed base efficient to administer while also allowing an orderly transition to a single firewall architecture. The key criteria were client separation, multi-site capability per firm, standardised procedures for updates, configurations and backups, and a repeatable, well documented setup of the DATEV connection.
The solution
With AIM – Advanced Infrastructure Management, a central management layer was placed across all customer environments. The administrators now work from a single interface:
- administer firms and sites with client separation
- prepare updates centrally and roll them out under control
- back up and restore configurations automatically
- distribute firewall rule sets in a standardised way, including the rule sets for the DATEV connection
- plan and support migrations centrally
Multi-client capability is the decisive element. Every firm remains cleanly separated from the others within the platform, even when it operates several sites. At the same time, the provider sees the entire installed base in one place. This turns the DATEV connection from an individual build per client into a rule set that is maintained once and rolled out repeatedly.
The platform was introduced within two weeks. The subsequent migration to AIMdefense runs without a fixed migration window. The existing installations are replaced step by step, with each firm moving at a point in time that suits it. Downtime during the migration is around ten minutes. The systems are configured to match the size and site structure of each firm and are supplied Assembled in Germany.
The result
The time spent on administration, updates and configuration maintenance fell by around 80 percent. The volume of tickets in firewall management fell by approximately 65 percent. Individual logins to distributed interfaces have largely been eliminated, and configuration states are backed up automatically.
For the managed service business, this means that the offering scales with the number of customers without the administrative effort growing at the same rate. New firms can be set up following a single pattern instead of building every environment individually. Maintenance and support of the platform continue alongside operations.
"In the past, our administrators had to open and maintain every firewall individually. With AIM we now manage more than 170 tax advisory environments centrally. Updates, rule sets, backups and migrations can be carried out in a far more structured way."
— Partner manager of the system house
Key facts
| Sector | IT system house / managed service provider |
|---|---|
| End customers | Tax advisory firms, more than 170 environments |
| AIM products | AIM, AIMdefense |
| Architecture | Multi-client and multi-site management |
| Focus | Secure DATEV connection, central firewall management |
| Previous systems | Various open source firewalls |
| Project duration | 2 weeks |
| Time saved in administration | around 80 % |
| Reduction in ticket volume | around 65 % |
| Migration window | Continuous, during ongoing operations |
| Downtime | around 10 minutes |
| Follow-on services | Maintenance and support |
More about AIM
For the modules behind client administration, configuration backup and firewall management, please see the Modules page.