The experience comes from operating publicly reachable infrastructure that is scanned and attacked every day: an own autonomous system, hundreds of servers, firewalls and filters that have to fend off attacks without disturbing legitimate traffic.
What is included
- OPNsense and pfSense: setup on suitable hardware or as a VM, rule set, NAT, aliases, schedules, high availability with CARP
- Linux firewalls with nftables or iptables, Fail2ban, rate limiting and filters against brute force and scans on servers
- Network segmentation with VLANs and zones: office, servers, guests, IoT, telephony and production cleanly separated
- IDS/IPS with Suricata or Zenarmor, geoblocking, threat lists, DNS filtering and logging
- Rule set review of existing firewalls (including Fortinet, Sophos, Cisco, UniFi, MikroTik) with report and cleanup
- Secure remote access: VPN integration, two-factor authentication, no open management ports
- Firewalls for data centres and hosting: edge filters, anti-spoofing, interaction with DDoS protection
- Documentation, change log and configuration backup, training of your team
Typical assignments
- A company replaces a provider router with an OPNsense firewall with VLANs, guest network, IDS and VPN.
- A grown rule set with 400 rules is analysed, reduced to 60 comprehensible rules and documented.
- A manufacturing company separates the machine network from the office so that an infected workstation can no longer reach any plant.
- Servers of a hosting provider get nftables rule sets and rate limiting against brute force, rolled out with Ansible.
Process
Request
Describe your needs briefly via the form, WhatsApp or the live chat.
Assessment
Within one business day you receive an assessment with effort, price and a proposed date.
Implementation
I do the work personally, remotely via secured access or on site, and keep you updated throughout.
Handover and invoice
Documented handover, then an invoice from KernelHost GmbH with convenient payment via kernelhost.com.
Questions about this service
OPNsense or a commercial product?
OPNsense offers enterprise features without licence costs and can be audited completely. Commercial firewalls are worthwhile when vendor support, central management of many sites or specific certifications are required. I advise vendor-neutrally and look after both.
Can you review our existing firewall without replacing it?
Yes. A rule set review delivers a report with redundant, risky and missing rules. Afterwards you decide whether I clean up or your team takes it over.
Is the firewall in the provider router enough?
For a home office perhaps, for a company not. Provider routers offer no segmentation, no IDS/IPS, no clean VPN options and rarely timely updates. An own firewall behind it costs little and creates control.
Remote for companies across Austria, combined with on-site appointments in Vienna on request.