Security engineering
Protecting critical infrastructure at the architecture level
Firewall architecture on FortiGate and Palo Alto, HA, segmentation, IPsec, routing integration and policy management — wired into logging and SIEM, by certified engineers.
The problem
The firewall is there; nobody knows what the policy still allows
The rules accumulated over years — the "temporary" permits added during an incident were never removed, an any/any turned up at the bottom, the segmentation exists only on the diagram, and the logs stay on the device itself and roll over within a week. The firewall was designed separately from routing, and now nobody can change either one safely.
- Unused and shadowed rules
- Segmentation is on the diagram, not in the configuration
- Logs stay on the device, leaving no audit trail
- A single node with no HA pair
What we deliver
Protecting critical infrastructure at the architecture level
Policy audit
Which rules are used, which are shadowed, and which allow more than anyone intended.
Zone model and segmentation
Zones, the VLAN/VRF split and an inter-zone matrix — the policy is written from that matrix.
HA architecture
The pair, session synchronisation and a failover that is actually exercised in a test.
IPsec and remote access
Branches, partners and staff — separate profiles rather than one shared tunnel.
Wiring into logging
Events off the device, with retention, search and correlation rules.
Configuration backup and change control
Automated export into version control, with an alert on every diff.
Architecture
Architecture
- 01AuditRules, zones and the externally visible surface
- Rule usage
- Shadowed rules
- 02Zone modelThe inter-zone matrix
- VLAN
- VRF
- Zones
- 03ValidateThe new policy in the lab, on the real topology
- EVE-NG
- Real topology
- 04ImplementZone by zone, with a rollback plan
- FortiGate
- PAN-OS
- HA cluster
- 05LoggingEvents off the device, with a retention period
- Graylog
- Wazuh
- rsyslog
- 06ReviewAn unused rule gets removed
- Git
- Diff alerts
Operator consoles
Operator consoles
These exact systems run on the group's own infrastructure — the screenshots are processed before publication.
The firewall — policy, sessions and load
A FortiGate in production: thousands of concurrent sessions, SPU load, security-fabric state and per-interface throughput on one screen. A firewall is not a separate box to us — it is designed and operated together with routing, segmentation and logging, by certified engineers.
WireGuard Portal — peers managed in one place
WireGuard is fast, but by default it is administered through config files — and by the twentieth peer that is a problem. The portal centralises key and peer management, adds self-service provisioning and shows who is connected right now. Interface state, MTU, DNS and keepalive on one screen.
public/media/proof/paloalto-firewall.webpnpm run proof:blurPalo Alto — policy at the application layer
The PAN-OS platform: App-ID and User-ID level policy, logging and threat prevention. We have engineers certified on it; a deployment screen goes up here once a specific production environment is cleared for publication.
Capabilities
Capabilities
Every item is marked: verified production experience, or engineering capability.
FortiGate architecture and HA
ProvenFortiGate in production: policy, an HA pair, IPsec and interface segmentation. We have engineers certified on the platform.
- FortiGate
- HA cluster
Palo Alto (PAN-OS) policy
CapabilityApp-ID and User-ID level policy, logging and threat prevention. The team includes engineers certified on PAN-OS.
- PAN-OS
- App-ID
- User-ID
Network segmentation
Proven- VLAN
- VRF
- Zones
IPsec and site-to-site VPN
Proven- IPsec
- IKEv2
- WireGuard
RPKI and routing security
Proven- RPKI
- ROA
- max-prefix
Policy management and audit
CapabilityConfiguration backup and recovery
Proven- Git
- Automated export
Process
Process
- 01
Audit
Rules, zones and the externally visible surface.
- 02
Zone design
The inter-zone matrix the policy is derived from.
- 03
Validate
The new policy in the lab, on the real topology.
- 04
Implement
Zone by zone, with a rollback plan.
- 05
Logging
Events off the device, retention and alerting.
- 06
Review
A periodic policy review — an unused rule gets removed.
Technology stack
Technology stack
- Firewall
- FortiGateFortiOSPAN-OSHA cluster
- VPN
- IPsecIKEv2WireGuardL2TP/IPsecSSTP
- Segmentation
- VLANVRFZones802.1X
- Routing security
- RPKIROARoutinatormax-prefix
- Logging
- GraylogWazuhOpenSearchrsyslog
- Configuration
- GitAutomated exportDiff alerts
Engagement model
Engagement model
Project
A one-off scope: audit, migration or implementation with a fixed outcome.
Retainer
Monthly engineering hours — specialist access on demand.
Co-managed
NetWizard and your in-house team together, with split responsibility.
Use cases
Use cases
One firewall, no spare
All traffic crosses one box and rebooting it is a night job. We build the HA pair, exercise the failover and record how many seconds the sessions took to come back.
An audit asked to see the rules
Documented zones, a justified policy and logs with a retention period are needed. We put all three in order and hand them over in a document an auditor can read.
Branches joining over VPN
Each site has its own circuit and its own risk. We build site-to-site tunnels with separate profiles, integrated with routing and visible in monitoring.
FAQ
FAQ
FortiGate or Palo Alto?
We operate FortiGate in production and have engineers certified on PAN-OS. The choice follows the requirements — throughput, application-layer policy, budget, and what your team already operates.
Can you migrate policy from one vendor to another?
We do not translate rules one for one — we reconstruct the zone model, write the policy from it and validate it in the lab. A one-to-one conversion carries the old rubbish across as well.
How does this connect to the SOC?
Firewall events are collected off the device on the logging platform; correlation and detection rules run there, and the remote SOC responds to what they raise.