Skip to content

Who this is for

For organisations that must demonstrate control over data access to an auditor, a client or an insurer.

What you get

  • Addressing, segmentation and routing design, documented in NetBox.
  • Dynamic routing configuration, including BGP, and redundant links.
  • Fortigate or IPFire firewall deployment together with access policies.
  • Remote access: IPsec VPN and zero-trust networks on Tailscale.
  • Web application protection: WAF, TLS termination, reverse proxy on HAProxy and Nginx.
  • Recurring vulnerability scanning with Greenbone plus a remediation plan.
  • Central logging in Graylog or Rsyslog as evidence during incidents.
  • Support for implementing and maintaining an ISO 27001 information security management system.

Problems I typically solve

  • The network is flat, so one infected workstation can reach production servers.
  • Remote access relies on port forwarding and shared passwords.
  • Nobody knows who changed a firewall rule, or when.
  • Logs are scattered across hosts, so incident analysis takes days.
  • An audit is coming and the network documentation has been out of date for years.

Stack involved

Networking

  • HAProxy
  • Nginx
  • BGP
  • DNS
  • Cisco
  • Juniper
  • IPFire
  • LACP / bonding
  • NetBox
  • Cloudflare

Security

  • Fortigate
  • WAF
  • IPsec VPN
  • Tailscale
  • OpenVPN
  • Greenbone
  • AlienVault
  • ISO 27001
  • Active Directory
  • ClamAV
  • Squid

Monitoring & logging

  • Zabbix
  • Grafana
  • New Relic
  • Percona Monitoring & Management
  • Rsyslog
  • Graylog

How I work

Four steps, always in this order

No audit means no design, no design means no rollout. This order saves money by the third step.

  1. Step 01

    Audit and analysis

    An inventory of what is actually running and a risk list ordered by business impact. Without this step everything that follows is guesswork.

  2. Step 02

    Architecture design

    The target shape of the environment, with cost, schedule and a rollback plan. Decisions are made before the rollout, not during it.

  3. Step 03

    Implementation

    Staged delivery, with configuration described in Ansible and Terraform. Every step is repeatable and reversible.

  4. Step 04

    Operations and monitoring

    Monitoring with thresholds tuned to real traffic, updates, restore testing and a report on the state of the environment.

Frequently asked questions

Contact

Describe the problem and get a specific answer

The fastest way to get to the point is to outline your current environment and what needs to change in your first message.

················