Why this exists

The problem Atlas Perimeter solves

Without Atlas Perimeter

The perimeter is a consumer router with ports open by default. No DMZ — web server and file server share the same VLAN. Remote access is RDP exposed to the internet. No IDS. A typical first Greenbone scan returns 15–40 critical findings on networks of this type.

With Atlas Perimeter

A deny-by-default firewall with documented rules reviewed quarterly. DMZ isolates public-facing services. Suricata drops known exploit traffic inline. WireGuard gives remote workers low-latency encrypted access without exposing RDP. Squid inspects all outbound HTTP/S. Greenbone scans weekly with credentialed checks — every new CVE detected within 7 days.

Architecture

How it works

Atlas Perimeter — zone model with WAN DMZ LAN and management VLAN
Architecture overview — Atlas Perimeter component relationships

Regulatory compliance

What Atlas Perimeter satisfies

Regulation / ControlRequirementAudit evidence
NIS2 Art. 21(2)(d)Network segmentation prevents lateral movement from compromised systemsOPNsense zone model export · inter-VLAN firewall rule log
NIS2 Art. 21(2)(h)Encrypted site-to-site VPN — no plaintext inter-site trafficWireGuard tunnel status · OPNsense VPN log
BSI NET.1.1Zone model, DMZ, VLAN segmentation, explicit inter-zone deny rulesOPNsense ruleset export · network diagram as-built
BSI NET.3.2Stateful inspection, deny-by-default, quarterly ruleset review documentedOPNsense ruleset with descriptions · change log in Git
GDPR Art. 32(1)(b)Network controls preventing unauthorised access to personal dataSuricata IPS event log · Squid access log
DORA Art. 13(2)Greenbone scanning evidences network security posture for threat-led testingGreenbone scan report · remediation tracking log

Standalone installation

Install one component — no full integration required

Each component can be deployed independently. Download the Customer Request Form, describe your environment, and we quote within 2 business days.

OPNsense firewall — standalone install

OPNsense 24.x on customer hardware or Protectli appliance. Three VLAN zones (WAN/DMZ/LAN). Deny-by-default ruleset — every rule documented. Suricata 7 IPS on WAN and DMZ. HAProxy for inbound load balancing. CARP if second unit available.

  • OPNsense 24.x + hardening
  • 3 VLAN zones with firewall rules
  • Suricata IPS (ET Open ruleset)
  • HAProxy inbound proxy
  • Documented ruleset in Git
  • 5-day post-install support

€ 810

Net, excl. VAT · travel within 100km Hamburg · hardware not included

Download CRF & request quote

WireGuard site-to-site VPN

WireGuard tunnel between 2 sites. Keypair generation. Firewall rules on both ends. Connectivity and failover test. Full config documented. Keys stored in Vault if Atlas Core deployed. Split-tunnel routing configured.

  • 2-site WireGuard tunnel
  • Key generation + Vault storage
  • Firewall rules both ends
  • Split-tunnel routing config
  • Connectivity test
  • 5-day post-install support

€ 460

Net, excl. VAT · travel within 100km Hamburg · hardware not included

Download CRF & request quote

Greenbone vulnerability scan

Greenbone Community Edition install and credentialed baseline scan of your internal hosts — no host cap. CVSS-scored findings. Remediation report with priority order. NIS2/BSI control mapping. One re-scan after top findings addressed. (Nessus available on request for an auditor-branded report.)

  • Greenbone CE install (no host cap)
  • Credentialed baseline scan
  • CVSS-scored findings report
  • NIS2/BSI control mapping
  • One re-scan after remediation

€ 390

Net, excl. VAT · travel within 100km Hamburg · hardware not included

Download CRF & request quote
Note: Standalone components do not include cross-product integration. To have it fitted into your existing environment, add the Integration package from the consulting section below.

Ready-made boxes

Foundation · Plus · Enterprise — fixed price, plug & play

Three boxes, three fixed prices. Each one ships pre-configured and pre-hardened: you power it up, work through a short quick-start guide, and it runs. No audit, no project phase, no consulting engagement required. Need it fitted into an existing environment instead? See the consulting packages below.

Foundation

5–50 users · 1 site · single server

Pre-configured · quick-start guide included

€ 1,890

Net, excl. VAT · one-off fixed price · hardware not included

  • OPNsense single node
  • WAN/DMZ/LAN zone model
  • Suricata IPS (ET Open)
  • WireGuard remote access VPN
  • Squid transparent proxy
Order this box
Enterprise

500+ users · multi-site · cluster-ready

Pre-configured · quick-start guide included

€ 3,290

Net, excl. VAT · one-off fixed price · hardware not included

  • OPNsense HA at all sites
  • IPsec for vendor/partner interop
  • Centralised Squid cluster
  • Greenbone continuous scan + Nessus Professional for auditor reports
  • Full SIEM correlation
Order this box

Consulting services

Need more than the box?

The boxes are built to run on their own. When you want one fitted into what you already have, add a fixed-price package — no open-ended day rates.

Installation & handover

We install the box in your environment, connect it to your network and DNS, and hand it over configured and documented. Remote, or on-site within 100 km of Hamburg.

  • Installed and connected on your side
  • Admin walkthrough session
  • Configuration handed over documented

€ 890

Net, excl. VAT · fixed price

Request this package

Integration into your environment

Connecting the box to what you already run — Active Directory, an existing DNS or firewall, your monitoring or SIEM — including migration of existing data.

  • Integration with 2 existing systems
  • Data / config migration
  • Rollback plan and test protocol

€ 1,890

Net, excl. VAT · fixed price

Request this package

Compliance mapping & audit support

We map the delivered configuration to NIS2, BSI IT-Grundschutz or DORA controls and hand over the evidence package your auditor will ask for.

  • Control mapping per regulation
  • Evidence package for the auditor
  • Gap list with remediation steps

€ 1,490

Net, excl. VAT · fixed price

Request this package
Larger scope? Multi-site rollouts, custom engineering and ongoing operations are quoted individually. Tell us what you need and we come back with a fixed price.

A Sophos alternative: GDPR-friendly, no licence fees

Facing a Sophos, Fortinet or SonicWall renewal? OPNsense is a mature open-source alternative to proprietary firewalls — no per-appliance licence fees and no mandatory subscription. It runs on your own hardware; your ruleset and logs stay entirely on-premises (GDPR-friendly, no cloud offloading, no data shared with third parties).

We migrate your existing ruleset, set up IPS (Suricata), site-to-site VPN and reporting, and hand over the full configuration — you keep root access and complete control. No vendor lock-in.