All work
Networking & SecurityProduction system2025
Firewall, VPN & IDS build-out
A segmented network with firewall policy, remote-access VPN and intrusion detection: built, attacked and documented.
Scope something similarCode walkthrough available on request
The problem
Flat networks with a consumer router are the norm in small offices, which means one compromised laptop reaches everything.
What we built
- pfSense firewall with explicit allow/deny policy, WAN/LAN separation and VLAN segmentation between zones
- Remote access over OpenVPN and IPSec, with DHCP and DNS resolution managed centrally
- Intrusion detection and prevention using Suricata and Snort, tuned against simulated attack scenarios
- Traffic analysis and verification with Wireshark and Nmap, plus scripted firewall-rule updates
- Step-by-step runbook and exported configuration so the build can be reproduced or handed over
Need something like this?
We'll tell you honestly whether your case is a two-week build or a three-month one — and what it would cost — before you commit to anything.