Control access, master the rules
We harden networks where attacks take effect: at the perimeter, across segments and at the port. Firewalls, segmentation, VPN and NAC — with rulebases someone will still understand in two years.
- Rulebase audits
- Segmentation with a plan
- NAC with Cisco ISE
- VPN for sites & remote work
From perimeter to port
Firewalling
Cisco ASA, Check Point and pfSense: design, migration and operations — including cleanup of grown rulebases.
Network segmentation
Zone model, VLAN and VRF design, policy concept: spread is contained, transitions become auditable.
VPN
Site-to-site and remote access: encrypted connectivity for sites, partners and employees.
NAC with Cisco ISE
802.1X, profiling and authorisation: only known devices join the network — with exactly the access they deserve.
Hardening & standards
Hardened device configurations, AAA, logging and management access following one clear standard.
Audit & cleanup
Grown rulebases are measured, documented and reduced — without interrupting operations.
How we proceed
Security is a state you can prove — this is how we get there.
Inventory
Rulebases, zones, access paths and exceptions are recorded and verified against reality.
Target picture & policy
Segmentation and access model with your team; security goals become rules, not intentions.
Implementation in waves
Changes run through change windows with pre-checks and rollback — security without downtime.
Evidence & operations
Documented rulebases, logs and a process that time-limits exceptions instead of forgetting them.
Tooling & platforms
- Cisco ASA
- Cisco ISE / NAC
- 802.1X
- Check Point
- pfSense
- IPsec VPN
- AAA / TACACS+
Next step
How solid is your rulebase?
We start with an audit: zones, rules, access paths and exceptions — assessed and returned with prioritised measures.
Request an audit