Skip to content
CONFIGLANE

Security & Access · Plan / Build / Operate

Network security that starts at the port

We harden networks where attacks take effect: at the perimeter, across segments and at the port. Firewalls, segmentation, VPN, NAC and vulnerability management — with rulebases someone will still understand in two years.

Discuss security

The exact scope follows your environment and its dependencies. Pricing, service hours and response targets are agreed in the proposal.

Scope

From perimeter to port

Network security as a craft: perimeter, segmentation and access control — implemented consistently, ready for any audit.

Firewalling

Cisco ASA, Check Point and pfSense: design, migration and operations — including cleanup of grown rulebases.

Network segmentation

Zone model, VLAN and VRF design, policy concept: spread is contained, transitions become auditable.

VPN

Site-to-site and remote access: encrypted connectivity for sites, partners and employees.

NAC with Cisco ISE

802.1X, profiling and authorisation: only known devices join the network — with exactly the access they deserve.

Hardening & standards

Hardened device configurations, AAA, logging and management access following one clear standard.

Vulnerability management

Recurring scans, assessment and risk-based prioritisation: vulnerabilities are found, tracked and closed — not just reported.

Approach

How we proceed

Security is a state you can prove — this is how we get there.

  1. Inventory

    Rulebases, zones, access paths and exceptions are recorded and verified against reality.

  2. Target picture & policy

    Segmentation and access model with your team; security goals become rules, not intentions.

  3. Implementation in waves

    Changes run through change windows with pre-checks and rollback — security without downtime.

  4. Evidence & operations

    Documented rulebases, logs and a process that time-limits exceptions instead of forgetting them.

In plain language

How segmentation and NAC protect your network

Why flat networks are dangerous, what NAC really delivers, how rulebooks stay auditable and why closing gaps is a process — explained soberly by CCNP-certified engineers.

Segmentation: fire compartments for your network

In a flat network, an attacker who takes over a single PC can reach everything from there — servers, finance, production. Segmentation builds fire walls: the network is divided into zones (office, servers, production, guests), and a firewall between the zones decides which traffic is genuinely needed. A compromised device stays contained in its compartment instead of moving sideways through the building. Against the spread of ransomware, this is the single most effective measure in the network.

NAC with Cisco ISE: identity checks at the network port

Network access control answers a simple question: who or what is connected to my network right now? With 802.1X, every device authenticates at the port or on the Wi-Fi like showing a staff badge — corporate laptops reach their network, guests reach the guest network, unknown devices stay out. Devices that cannot present a badge of their own, such as printers or machine controllers, are identified by their hardware address and receive exactly the access they need. Cisco ISE enforces those rules centrally — traceable for every single device.

Firewall rules you still understand a year later

Firewalls that grew over years are often a black box: hundreds of rules, nobody remembers what half of them are for — and nobody deletes them for fear of outages. We bring structure: named objects instead of bare IP addresses, a comment on every rule, regular clean-up of unused entries and a documented path for new requests. The rulebook stays auditable — for your team, for auditors, and for us.

Vulnerability management: close the gaps before someone finds them

New vulnerabilities become public every week — including in devices that counted as secure yesterday. Vulnerability management turns that into a process instead of a headline: recurring scans show which gaps are actually open in your network, an assessment ranks them by risk, and the critical ones are closed first — through an update, a configuration change or segmentation. Repetition is what matters: a single scan is a snapshot, an ongoing process keeps the risk down for good.

Visibility and evidence: security you can demonstrate

Frameworks like NIS2 and ISO 27001 demand the same things at their core: know what is on your network, control who gets access, and be able to prove both. That is exactly what segmentation, NAC and a documented rulebook provide as the technical foundation. We do not replace legal or compliance consulting — we build the network layer your evidence rests on.

Tooling & platforms

  • Cisco ASA
  • Cisco ISE / NAC
  • 802.1X
  • Check Point
  • pfSense
  • IPsec VPN
  • AAA / TACACS+

FAQ

Common questions about network security

Why is the firewall at the internet edge not enough?

It protects against attacks from outside — but once a device on the inside is compromised, and one click on a phishing mail is enough for that, it is powerless. Segmentation limits the damage on the inside: zones with controlled crossings prevent an attacker from moving freely through the network.

Does NAC work with older devices, printers and machines?

Yes. Devices that cannot speak 802.1X are admitted via MAC Authentication Bypass (MAB) based on their hardware address — with deliberately narrow permissions and their own segment. The exception does not drag down the security level of the rest of the network.

Does this help us with NIS2?

Segmentation, controlled network access and documented rules are technical building blocks that support central NIS2 requirements on risk management and access control. Whether your company falls under NIS2 and what is required organisationally is a matter for legal and compliance advice — we build the network layer for it.

Can segmentation be introduced during live operations?

Yes — step by step. First an analysis creates visibility into which traffic actually flows; then zones are enforced one after another, starting where risk and effort are in the best ratio. Every step has a maintenance window, measurable checkpoints and a way back.

We already have a firewall — is a review still worth it?

Especially then. Most rulebooks grow for years and contain openings nobody needs anymore. A review uncovers unused and risky rules, documents the inventory and delivers a plan that makes the rulebook manageable again — without buying new hardware.

Do you support security remotely?

Yes — analysis, rulebook maintenance, ISE operations and reviews run as a managed service, remote-first for clients across Germany and the EU. For initial surveys or rollouts we plan targeted on-site visits; day-to-day operations need no travel.

Does vulnerability management replace a penetration test?

No — the two complement each other. A pentest is a point-in-time deep dive from the attacker's perspective; vulnerability management is the ongoing process that continuously finds, risk-ranks and closes known gaps. We build that process and deliver the evidence — when a pentest comes up, it meets a prepared network.

Articles on this topic

Related services

Next step

How solid is your rulebase?

We start with an audit: zones, rules, access paths and exceptions — assessed and returned with prioritised measures.

Request an audit

Assessment → first dependable change