Skip to content

Security engineering

Protecting critical infrastructure at the architecture level

Firewall architecture on FortiGate and Palo Alto, HA, segmentation, IPsec, routing integration and policy management — wired into logging and SIEM, by certified engineers.

The problem

The firewall is there; nobody knows what the policy still allows

The rules accumulated over years — the "temporary" permits added during an incident were never removed, an any/any turned up at the bottom, the segmentation exists only on the diagram, and the logs stay on the device itself and roll over within a week. The firewall was designed separately from routing, and now nobody can change either one safely.

  • Unused and shadowed rules
  • Segmentation is on the diagram, not in the configuration
  • Logs stay on the device, leaving no audit trail
  • A single node with no HA pair

What we deliver

Protecting critical infrastructure at the architecture level

Policy audit

Which rules are used, which are shadowed, and which allow more than anyone intended.

Zone model and segmentation

Zones, the VLAN/VRF split and an inter-zone matrix — the policy is written from that matrix.

HA architecture

The pair, session synchronisation and a failover that is actually exercised in a test.

IPsec and remote access

Branches, partners and staff — separate profiles rather than one shared tunnel.

Wiring into logging

Events off the device, with retention, search and correlation rules.

Configuration backup and change control

Automated export into version control, with an alert on every diff.

Architecture

Architecture

  1. 01AuditRules, zones and the externally visible surface
    • Rule usage
    • Shadowed rules
  2. 02Zone modelThe inter-zone matrix
    • VLAN
    • VRF
    • Zones
  3. 03ValidateThe new policy in the lab, on the real topology
    • EVE-NG
    • Real topology
  4. 04ImplementZone by zone, with a rollback plan
    • FortiGate
    • PAN-OS
    • HA cluster
  5. 05LoggingEvents off the device, with a retention period
    • Graylog
    • Wazuh
    • rsyslog
  6. 06ReviewAn unused rule gets removed
    • Git
    • Diff alerts
The path of a policy — from the matrix to the rule, and back to review

Operator consoles

Operator consoles

These exact systems run on the group's own infrastructure — the screenshots are processed before publication.

Blurred FortiGate dashboard: session, memory and throughput graphs with security-fabric status.

The firewall — policy, sessions and load

A FortiGate in production: thousands of concurrent sessions, SPU load, security-fabric state and per-interface throughput on one screen. A firewall is not a separate box to us — it is designed and operated together with routing, segmentation and logging, by certified engineers.

FortiGateHAsegmentationIPsec
The WireGuard Portal interface administration screen — peer counts and interface parameters; keys and addresses are redacted.

WireGuard Portal — peers managed in one place

WireGuard is fast, but by default it is administered through config files — and by the twentieth peer that is a problem. The portal centralises key and peer management, adds self-service provisioning and shows who is connected right now. Interface state, MTU, DNS and keepalive on one screen.

WireGuardpeer managementself-serviceMikroTik
screenshot not supplied yetpublic/media/proof/paloalto-firewall.webpnpm run proof:blur
Palo Alto · PAN-OSblurred

Palo Alto — policy at the application layer

The PAN-OS platform: App-ID and User-ID level policy, logging and threat prevention. We have engineers certified on it; a deployment screen goes up here once a specific production environment is cleared for publication.

PAN-OSApp-IDUser-IDthreat prevention

Capabilities

Capabilities

Every item is marked: verified production experience, or engineering capability.

FortiGate architecture and HA

Proven

FortiGate in production: policy, an HA pair, IPsec and interface segmentation. We have engineers certified on the platform.

  • FortiGate
  • HA cluster

Palo Alto (PAN-OS) policy

Capability

App-ID and User-ID level policy, logging and threat prevention. The team includes engineers certified on PAN-OS.

  • PAN-OS
  • App-ID
  • User-ID

Network segmentation

Proven
  • VLAN
  • VRF
  • Zones

IPsec and site-to-site VPN

Proven
  • IPsec
  • IKEv2
  • WireGuard

RPKI and routing security

Proven
  • RPKI
  • ROA
  • max-prefix

Policy management and audit

Capability

Configuration backup and recovery

Proven
  • Git
  • Automated export

Process

Process

  1. 01

    Audit

    Rules, zones and the externally visible surface.

  2. 02

    Zone design

    The inter-zone matrix the policy is derived from.

  3. 03

    Validate

    The new policy in the lab, on the real topology.

  4. 04

    Implement

    Zone by zone, with a rollback plan.

  5. 05

    Logging

    Events off the device, retention and alerting.

  6. 06

    Review

    A periodic policy review — an unused rule gets removed.

Technology stack

Technology stack

Firewall
FortiGateFortiOSPAN-OSHA cluster
VPN
IPsecIKEv2WireGuardL2TP/IPsecSSTP
Segmentation
VLANVRFZones802.1X
Routing security
RPKIROARoutinatormax-prefix
Logging
GraylogWazuhOpenSearchrsyslog
Configuration
GitAutomated exportDiff alerts

Engagement model

Engagement model

Project

A one-off scope: audit, migration or implementation with a fixed outcome.

Retainer

Monthly engineering hours — specialist access on demand.

Co-managed

NetWizard and your in-house team together, with split responsibility.

Use cases

Use cases

One firewall, no spare

All traffic crosses one box and rebooting it is a night job. We build the HA pair, exercise the failover and record how many seconds the sessions took to come back.

An audit asked to see the rules

Documented zones, a justified policy and logs with a retention period are needed. We put all three in order and hand them over in a document an auditor can read.

Branches joining over VPN

Each site has its own circuit and its own risk. We build site-to-site tunnels with separate profiles, integrated with routing and visible in monitoring.

FAQ

FAQ

FortiGate or Palo Alto?

We operate FortiGate in production and have engineers certified on PAN-OS. The choice follows the requirements — throughput, application-layer policy, budget, and what your team already operates.

Can you migrate policy from one vendor to another?

We do not translate rules one for one — we reconstruct the zone model, write the policy from it and validate it in the lab. A one-to-one conversion carries the old rubbish across as well.

How does this connect to the SOC?

Firewall events are collected off the device on the logging platform; correlation and detection rules run there, and the remote SOC responds to what they raise.

Tell us about your infrastructure