Why this exists

The problem Atlas Perimeter solves

Without Atlas Perimeter

The perimeter is a consumer router with ports open by default. No DMZ — web server and file server share the same VLAN. Remote access is RDP exposed to the internet. No IDS. A typical first Greenbone scan returns 15–40 critical findings on networks of this type.

With Atlas Perimeter

A deny-by-default firewall with documented rules reviewed quarterly. DMZ isolates public-facing services. Suricata drops known exploit traffic inline. WireGuard gives remote workers low-latency encrypted access without exposing RDP. Squid inspects all outbound HTTP/S. Greenbone scans weekly with credentialed checks — every new CVE detected within 7 days.

Architecture

How it works

Atlas Perimeter — zone model with WAN DMZ LAN and management VLAN
Architecture overview — Atlas Perimeter component relationships

Regulatory compliance

What Atlas Perimeter satisfies

Regulation / ControlRequirementAudit evidence
NIS2 Art. 21(2)(d)Network segmentation prevents lateral movement from compromised systemsOPNsense zone model export · inter-VLAN firewall rule log
NIS2 Art. 21(2)(h)Encrypted site-to-site VPN — no plaintext inter-site trafficWireGuard tunnel status · OPNsense VPN log
BSI NET.1.1Zone model, DMZ, VLAN segmentation, explicit inter-zone deny rulesOPNsense ruleset export · network diagram as-built
BSI NET.3.2Stateful inspection, deny-by-default, quarterly ruleset review documentedOPNsense ruleset with descriptions · change log in Git
GDPR Art. 32(1)(b)Network controls preventing unauthorised access to personal dataSuricata IPS event log · Squid access log
DORA Art. 13(2)Greenbone scanning evidences network security posture for threat-led testingGreenbone scan report · remediation tracking log

Standalone installation

Install one component — no full integration required

Each component can be deployed independently. Download the Customer Request Form, describe your environment, and we quote within 2 business days.

OPNsense firewall — standalone install

OPNsense 24.x on customer hardware or Protectli appliance. Three VLAN zones (WAN/DMZ/LAN). Deny-by-default ruleset — every rule documented. Suricata 7 IPS on WAN and DMZ. HAProxy for inbound load balancing. CARP if second unit available.

  • OPNsense 24.x + hardening
  • 3 VLAN zones with firewall rules
  • Suricata IPS (ET Open ruleset)
  • HAProxy inbound proxy
  • Documented ruleset in Git
  • 5-day post-install support

€ 1,490

Net, excl. VAT · travel within 100km Hamburg · hardware not included

Download CRF & request quote

WireGuard site-to-site VPN

WireGuard tunnel between 2 sites. Keypair generation. Firewall rules on both ends. Connectivity and failover test. Full config documented. Keys stored in Vault if Atlas Core deployed. Split-tunnel routing configured.

  • 2-site WireGuard tunnel
  • Key generation + Vault storage
  • Firewall rules both ends
  • Split-tunnel routing config
  • Connectivity test
  • 5-day post-install support

€ 890

Net, excl. VAT · travel within 100km Hamburg · hardware not included

Download CRF & request quote

Greenbone vulnerability scan

Greenbone Community Edition install and credentialed baseline scan of your internal hosts — no host cap. CVSS-scored findings. Remediation report with priority order. NIS2/BSI control mapping. One re-scan after top findings addressed. (Nessus available on request for an auditor-branded report.)

  • Greenbone CE install (no host cap)
  • Credentialed baseline scan
  • CVSS-scored findings report
  • NIS2/BSI control mapping
  • One re-scan after remediation

€ 690

Net, excl. VAT · travel within 100km Hamburg · hardware not included

Download CRF & request quote
Note: Standalone components do not include cross-product integration. Full Atlas Perimeter integration — connecting it into your existing environment — starts with an audit engagement.

Full integration

Foundation · Plus · Enterprise

Full integration starts with a 2–3 week audit. XpertOne maps your existing environment, identifies gaps, and produces a fixed-price statement of work. On-site engineer included for the full integration period.

Foundation

5–50 users · 1 site · 1 month on-site

1 month on-site

from € 16,800

Net, excl. VAT · fixed price scoped by audit

  • OPNsense single node
  • WAN/DMZ/LAN zone model
  • Suricata IPS (ET Open)
  • WireGuard remote access VPN
  • Squid transparent proxy
  • Greenbone baseline scan
  • Documented ruleset
Request audit to start
Enterprise

500+ users · multi-site · 6 months on-site

6 months on-site

from € 90,000

Net, excl. VAT · fixed price scoped by audit

  • OPNsense HA at all sites
  • IPsec for vendor/partner interop
  • Centralised Squid cluster
  • Greenbone continuous scan + Nessus Professional for auditor reports
  • Full SIEM correlation
  • ISO 27001 firewall evidence package
  • Quarterly ruleset audit
Request audit to start

A Sophos alternative: GDPR-friendly, no licence fees

Facing a Sophos, Fortinet or SonicWall renewal? OPNsense is a mature open-source alternative to proprietary firewalls — no per-appliance licence fees and no mandatory subscription. It runs on your own hardware; your ruleset and logs stay entirely on-premises (GDPR-friendly, no cloud offloading, no data shared with third parties).

We migrate your existing ruleset, set up IPS (Suricata), site-to-site VPN and reporting, and hand over the full configuration — you keep root access and complete control. No vendor lock-in.

Start with an audit

All integration engagements begin with a 2–3 week technical audit. The audit is a paid engagement producing a gap analysis, architecture recommendation, and fixed-price statement of work.

Request audit engagement