1U Firewall -- router-adjacent, deep-packet-inspection enabled. Sits alongside (not instead of) a router: it doesn't hold the ISP uplink itself, but it's what actually earns the defensive benefit of "properly configured" security posture.
5Gbps throughput, one WAN port, three LAN ports, 200000 concurrent sessions, 512 rules, DPI enabled -- a real inspection budget, not just a rule list.
Measurably dampens Heat accrual and speeds its decay versus running unprotected -- Heat rises with revenue activity and decays over time regardless, but a live, correctly-wired firewall changes both rates in your favor.
That Heat benefit costs more config work than a plain router's built-in firewall rules: it needs its own WAN/LAN wiring done correctly to actually be "live" for the Heat calculation, not just powered on and sitting in the rack.
Tip: if Heat is climbing faster than expected despite having a firewall racked, double check it's actually wired into the traffic path (WAN in, LAN out to the rest of the rack) -- an unwired firewall gets none of the benefit despite showing as powered.
See also: the Game Systems manual's Hacker System section for Heat, intrusions, and the recurring hacker collective storyline.