Remote for Austria

Firewall and network security: OPNsense, segmentation, IDS/IPS

A firewall only protects as well as its rule set. In many companies it has grown over years, nobody knows what each rule is for any more, and an allow-everything rule sits somewhere at the top. I design and operate firewalls for sites, data centres and server landscapes, from OPNsense and pfSense to nftables on Linux servers, with rule sets that are documented and verifiable.

The experience comes from operating publicly reachable infrastructure that is scanned and attacked every day: an own autonomous system, hundreds of servers, firewalls and filters that have to fend off attacks without disturbing legitimate traffic.

What is included

  • OPNsense and pfSense: setup on suitable hardware or as a VM, rule set, NAT, aliases, schedules, high availability with CARP
  • Linux firewalls with nftables or iptables, Fail2ban, rate limiting and filters against brute force and scans on servers
  • Network segmentation with VLANs and zones: office, servers, guests, IoT, telephony and production cleanly separated
  • IDS/IPS with Suricata or Zenarmor, geoblocking, threat lists, DNS filtering and logging
  • Rule set review of existing firewalls (including Fortinet, Sophos, Cisco, UniFi, MikroTik) with report and cleanup
  • Secure remote access: VPN integration, two-factor authentication, no open management ports
  • Firewalls for data centres and hosting: edge filters, anti-spoofing, interaction with DDoS protection
  • Documentation, change log and configuration backup, training of your team

Typical assignments

  • A company replaces a provider router with an OPNsense firewall with VLANs, guest network, IDS and VPN.
  • A grown rule set with 400 rules is analysed, reduced to 60 comprehensible rules and documented.
  • A manufacturing company separates the machine network from the office so that an infected workstation can no longer reach any plant.
  • Servers of a hosting provider get nftables rule sets and rate limiting against brute force, rolled out with Ansible.

Process

  1. Request

    Describe your needs briefly via the form, WhatsApp or the live chat.

  2. Assessment

    Within one business day you receive an assessment with effort, price and a proposed date.

  3. Implementation

    I do the work personally, remotely via secured access or on site, and keep you updated throughout.

  4. Handover and invoice

    Documented handover, then an invoice from KernelHost GmbH with convenient payment via kernelhost.com.

Questions about this service

OPNsense or a commercial product?

OPNsense offers enterprise features without licence costs and can be audited completely. Commercial firewalls are worthwhile when vendor support, central management of many sites or specific certifications are required. I advise vendor-neutrally and look after both.

Can you review our existing firewall without replacing it?

Yes. A rule set review delivers a report with redundant, risky and missing rules. Afterwards you decide whether I clean up or your team takes it over.

Is the firewall in the provider router enough?

For a home office perhaps, for a company not. Provider routers offer no segmentation, no IDS/IPS, no clean VPN options and rarely timely updates. An own firewall behind it costs little and creates control.

Remote for companies across Austria, combined with on-site appointments in Vienna on request.

Ready to discuss your project?

Describe your project in a few sentences, remote or on site in Vienna. You will receive an assessment with effort and price within one business day.