Networking & security
I design networks that can grow and secure them in layers, from segmentation and firewalls to central logging and regular vulnerability scanning.
Request a quoteWho this is for
For organisations that must demonstrate control over data access to an auditor, a client or an insurer.
What you get
- Addressing, segmentation and routing design, documented in NetBox.
- Dynamic routing configuration, including BGP, and redundant links.
- Fortigate or IPFire firewall deployment together with access policies.
- Remote access: IPsec VPN and zero-trust networks on Tailscale.
- Web application protection: WAF, TLS termination, reverse proxy on HAProxy and Nginx.
- Recurring vulnerability scanning with Greenbone plus a remediation plan.
- Central logging in Graylog or Rsyslog as evidence during incidents.
- Support for implementing and maintaining an ISO 27001 information security management system.
Problems I typically solve
- The network is flat, so one infected workstation can reach production servers.
- Remote access relies on port forwarding and shared passwords.
- Nobody knows who changed a firewall rule, or when.
- Logs are scattered across hosts, so incident analysis takes days.
- An audit is coming and the network documentation has been out of date for years.
Stack involved
Networking
- HAProxy
- Nginx
- BGP
- DNS
- Cisco
- Juniper
- IPFire
- LACP / bonding
- NetBox
- Cloudflare
Security
- Fortigate
- WAF
- IPsec VPN
- Tailscale
- OpenVPN
- Greenbone
- AlienVault
- ISO 27001
- Active Directory
- ClamAV
- Squid
Monitoring & logging
- Zabbix
- Grafana
- New Relic
- Percona Monitoring & Management
- Rsyslog
- Graylog
How I work
Four steps, always in this order
No audit means no design, no design means no rollout. This order saves money by the third step.
Step 01
Audit and analysis
An inventory of what is actually running and a risk list ordered by business impact. Without this step everything that follows is guesswork.
Step 02
Architecture design
The target shape of the environment, with cost, schedule and a rollback plan. Decisions are made before the rollout, not during it.
Step 03
Implementation
Staged delivery, with configuration described in Ansible and Terraform. Every step is repeatable and reversible.
Step 04
Operations and monitoring
Monitoring with thresholds tuned to real traffic, updates, restore testing and a report on the state of the environment.
Frequently asked questions
Contact
Describe the problem and get a specific answer
The fastest way to get to the point is to outline your current environment and what needs to change in your first message.