// Firewall and VPN · for Düsseldorf & the Rhine-Ruhr region
Firewall and VPN solutions
What comes in and what goes out is decided at the border of your network. We build that crossing, maintain the rule base and give your people a way in from outside that does not bring the whole network with it.
// The crossing
The border is the last place where you can still decide
Everything knocking at your network from the internet passes one point. That makes it the most valuable spot in your infrastructure: here you can still refuse things wholesale that would take real effort to catch once inside. And here is where the log gets written that shows, in case of doubt, what actually happened.
In practice that point is often a box somebody configured years ago and which has run ever since. It does its job, but nobody can say which releases are still in it, whether support is still valid, or who last entered an exception.
So we treat the crossing as something that gets maintained: a documented rule base, changes you can follow afterwards, and a fixed date on which every release is questioned again.
// Three jobs
What meets at the network edge
Firewall and VPN are often thought about separately. In daily operation they hang at the same point and have to fit each other.
A controlled crossing
- Reachable only what has to be reachable
- Outbound traffic is restricted as well
- Releases are documented and carry an end date
- Logs that give you an answer when you need one
Remote access with limits
- A second factor at every sign-in
- Access to the systems required, not to everything
- Managed devices at the far end of the tunnel
- Accounts that expire the day somebody leaves
Buildings joined up
- Branch, warehouse and head office work as one network
- Rules between the sites instead of a clear view across
- A second path for routes that have to stay up
- A design that tolerates one more site being added
// Remote access
Home working and field staff without a back door
-
Sign-in with a second factor
A password on its own is not enough, because credentials get traded. The second factor makes a stolen login worthless by itself.
-
Only as much network as needed
Accounts payable needs the business application, not the machine controller. Access leads to where the work happens and nowhere else.
-
A known device at the far end
A tunnel is only as trustworthy as the computer that builds it. Managed devices come in; unknown private machines do not.
-
Accounts with an end date
Contractors and temporary staff get access for a period. Whoever leaves loses it the same day, not at the next clear-out.
// Operation
Rules age faster than hardware
Every release had a good reason once. The trouble is that the reason disappears and the release stays: the project ended, the contractor is no longer on site, the test server was switched off long ago — and the open door to it is still there.
So we walk the rule base regularly and put the same question to every entry: what is it for, who needs it, and what breaks if we close it? Anything nobody can still explain comes out — announced beforehand, so that nobody is caught out.
On top of that comes care of the box itself: current firmware, valid support, and a saved configuration that lets the crossing be rebuilt quickly after a failure. Under a support agreement we take on both.
// Questions about firewall and VPN
What comes up again and again at the network edge
01 Is the router from our internet provider enough as a firewall?
For a household, yes. For a business, rarely. It has no separated zones, no logs you can work with, and rule management that goes little beyond port forwarding. Above all it offers no view inside: you see that things work, not what is passing through.
02 We have a firewall. Is a one-time setup enough?
No, and this is the most common finding of all. Rule bases grow: a release opened for a project stays, a test route is never removed. After a few years more stands open than anybody ever intended. Rules need a scheduled review.
03 Is a VPN outdated if we work in the cloud anyway?
For purely cloud-based applications you need no tunnel at all. But as soon as a business application, a file server or a machine sits in your own building, some route leads there — and that route is better handled as controlled access than as a port opened to the internet.
04 What makes remote access that does not become the risk itself?
A second factor at sign-in, access that leads only to the systems required, and a managed device at the far end. A tunnel that pulls a private computer fully into the company network simply moves the problem inside.
05 How do you link several sites?
Through encrypted connections between the sites, so branch, warehouse and head office work as one network — with rules in between, so that not every site sees everything. On routes the business depends on we plan a second path for line failure.
06 Will you take over an existing firewall?
As a rule, yes. We start by reading the rule base that has grown over the years and clearing it up, rather than replacing kit on principle. A swap becomes the sensible option when support or feature set no longer match what your business needs today.
Related
Cybersecurity overview
When did anyone last read your firewall rules?
We go through the rule base with you, mark what nobody can still explain and say which of it belongs closed straight away.