Atlas Perimeter
Firewall & Site-to-Site VPN
Deny-by-default firewall, inline IPS, and your own VPN — enterprise perimeter security on open-source you control, with zero licence fees.
Why this exists
Without Atlas Perimeter
The perimeter is a consumer router with ports open by default. No DMZ — web server and file server share the same VLAN. Remote access is RDP exposed to the internet. No IDS. A typical first Greenbone scan returns 15–40 critical findings on networks of this type.
With Atlas Perimeter
A deny-by-default firewall with documented rules reviewed quarterly. DMZ isolates public-facing services. Suricata drops known exploit traffic inline. WireGuard gives remote workers low-latency encrypted access without exposing RDP. Squid inspects all outbound HTTP/S. Greenbone scans weekly with credentialed checks — every new CVE detected within 7 days.
Architecture
Regulatory compliance
| Regulation / Control | Requirement | Audit evidence |
|---|---|---|
| NIS2 Art. 21(2)(d) | Network segmentation prevents lateral movement from compromised systems | OPNsense zone model export · inter-VLAN firewall rule log |
| NIS2 Art. 21(2)(h) | Encrypted site-to-site VPN — no plaintext inter-site traffic | WireGuard tunnel status · OPNsense VPN log |
| BSI NET.1.1 | Zone model, DMZ, VLAN segmentation, explicit inter-zone deny rules | OPNsense ruleset export · network diagram as-built |
| BSI NET.3.2 | Stateful inspection, deny-by-default, quarterly ruleset review documented | OPNsense ruleset with descriptions · change log in Git |
| GDPR Art. 32(1)(b) | Network controls preventing unauthorised access to personal data | Suricata IPS event log · Squid access log |
| DORA Art. 13(2) | Greenbone scanning evidences network security posture for threat-led testing | Greenbone scan report · remediation tracking log |
Standalone installation
Each component can be deployed independently. Download the Customer Request Form, describe your environment, and we quote within 2 business days.
OPNsense firewall — standalone install
OPNsense 24.x on customer hardware or Protectli appliance. Three VLAN zones (WAN/DMZ/LAN). Deny-by-default ruleset — every rule documented. Suricata 7 IPS on WAN and DMZ. HAProxy for inbound load balancing. CARP if second unit available.
€ 810
Net, excl. VAT · travel within 100km Hamburg · hardware not included
Download CRF & request quoteWireGuard site-to-site VPN
WireGuard tunnel between 2 sites. Keypair generation. Firewall rules on both ends. Connectivity and failover test. Full config documented. Keys stored in Vault if Atlas Core deployed. Split-tunnel routing configured.
€ 460
Net, excl. VAT · travel within 100km Hamburg · hardware not included
Download CRF & request quoteGreenbone vulnerability scan
Greenbone Community Edition install and credentialed baseline scan of your internal hosts — no host cap. CVSS-scored findings. Remediation report with priority order. NIS2/BSI control mapping. One re-scan after top findings addressed. (Nessus available on request for an auditor-branded report.)
€ 390
Net, excl. VAT · travel within 100km Hamburg · hardware not included
Download CRF & request quoteReady-made boxes
Three boxes, three fixed prices. Each one ships pre-configured and pre-hardened: you power it up, work through a short quick-start guide, and it runs. No audit, no project phase, no consulting engagement required. Need it fitted into an existing environment instead? See the consulting packages below.
5–50 users · 1 site · single server
€ 1,890
Net, excl. VAT · one-off fixed price · hardware not included
50–500 users · 1–5 sites · HA-ready
€ 2,540
Net, excl. VAT · one-off fixed price · hardware not included
500+ users · multi-site · cluster-ready
€ 3,290
Net, excl. VAT · one-off fixed price · hardware not included
Consulting services
The boxes are built to run on their own. When you want one fitted into what you already have, add a fixed-price package — no open-ended day rates.
Installation & handover
We install the box in your environment, connect it to your network and DNS, and hand it over configured and documented. Remote, or on-site within 100 km of Hamburg.
€ 890
Net, excl. VAT · fixed price
Request this packageIntegration into your environment
Connecting the box to what you already run — Active Directory, an existing DNS or firewall, your monitoring or SIEM — including migration of existing data.
€ 1,890
Net, excl. VAT · fixed price
Request this packageCompliance mapping & audit support
We map the delivered configuration to NIS2, BSI IT-Grundschutz or DORA controls and hand over the evidence package your auditor will ask for.
€ 1,490
Net, excl. VAT · fixed price
Request this packageFacing a Sophos, Fortinet or SonicWall renewal? OPNsense is a mature open-source alternative to proprietary firewalls — no per-appliance licence fees and no mandatory subscription. It runs on your own hardware; your ruleset and logs stay entirely on-premises (GDPR-friendly, no cloud offloading, no data shared with third parties).
We migrate your existing ruleset, set up IPS (Suricata), site-to-site VPN and reporting, and hand over the full configuration — you keep root access and complete control. No vendor lock-in.
Copyright © XpertOne Security Consulting GmbH. All Rights Reserved. | Impressum | Datenschutz