Atlas Perimeter
Firewall & Site-to-Site VPN
Deny-by-default firewall, inline IPS, and your own VPN — enterprise perimeter security on open-source you control, with zero licence fees.
Why this exists
Without Atlas Perimeter
The perimeter is a consumer router with ports open by default. No DMZ — web server and file server share the same VLAN. Remote access is RDP exposed to the internet. No IDS. A typical first Greenbone scan returns 15–40 critical findings on networks of this type.
With Atlas Perimeter
A deny-by-default firewall with documented rules reviewed quarterly. DMZ isolates public-facing services. Suricata drops known exploit traffic inline. WireGuard gives remote workers low-latency encrypted access without exposing RDP. Squid inspects all outbound HTTP/S. Greenbone scans weekly with credentialed checks — every new CVE detected within 7 days.
Architecture
Regulatory compliance
| Regulation / Control | Requirement | Audit evidence |
|---|---|---|
| NIS2 Art. 21(2)(d) | Network segmentation prevents lateral movement from compromised systems | OPNsense zone model export · inter-VLAN firewall rule log |
| NIS2 Art. 21(2)(h) | Encrypted site-to-site VPN — no plaintext inter-site traffic | WireGuard tunnel status · OPNsense VPN log |
| BSI NET.1.1 | Zone model, DMZ, VLAN segmentation, explicit inter-zone deny rules | OPNsense ruleset export · network diagram as-built |
| BSI NET.3.2 | Stateful inspection, deny-by-default, quarterly ruleset review documented | OPNsense ruleset with descriptions · change log in Git |
| GDPR Art. 32(1)(b) | Network controls preventing unauthorised access to personal data | Suricata IPS event log · Squid access log |
| DORA Art. 13(2) | Greenbone scanning evidences network security posture for threat-led testing | Greenbone scan report · remediation tracking log |
Standalone installation
Each component can be deployed independently. Download the Customer Request Form, describe your environment, and we quote within 2 business days.
OPNsense firewall — standalone install
OPNsense 24.x on customer hardware or Protectli appliance. Three VLAN zones (WAN/DMZ/LAN). Deny-by-default ruleset — every rule documented. Suricata 7 IPS on WAN and DMZ. HAProxy for inbound load balancing. CARP if second unit available.
€ 1,490
Net, excl. VAT · travel within 100km Hamburg · hardware not included
Download CRF & request quoteWireGuard site-to-site VPN
WireGuard tunnel between 2 sites. Keypair generation. Firewall rules on both ends. Connectivity and failover test. Full config documented. Keys stored in Vault if Atlas Core deployed. Split-tunnel routing configured.
€ 890
Net, excl. VAT · travel within 100km Hamburg · hardware not included
Download CRF & request quoteGreenbone vulnerability scan
Greenbone Community Edition install and credentialed baseline scan of your internal hosts — no host cap. CVSS-scored findings. Remediation report with priority order. NIS2/BSI control mapping. One re-scan after top findings addressed. (Nessus available on request for an auditor-branded report.)
€ 690
Net, excl. VAT · travel within 100km Hamburg · hardware not included
Download CRF & request quoteFull integration
Full integration starts with a 2–3 week audit. XpertOne maps your existing environment, identifies gaps, and produces a fixed-price statement of work. On-site engineer included for the full integration period.
5–50 users · 1 site · 1 month on-site
from € 16,800
Net, excl. VAT · fixed price scoped by audit
50–500 users · multi-site · 3 months on-site
from € 42,000
Net, excl. VAT · fixed price scoped by audit
500+ users · multi-site · 6 months on-site
from € 90,000
Net, excl. VAT · fixed price scoped by audit
Facing a Sophos, Fortinet or SonicWall renewal? OPNsense is a mature open-source alternative to proprietary firewalls — no per-appliance licence fees and no mandatory subscription. It runs on your own hardware; your ruleset and logs stay entirely on-premises (GDPR-friendly, no cloud offloading, no data shared with third parties).
We migrate your existing ruleset, set up IPS (Suricata), site-to-site VPN and reporting, and hand over the full configuration — you keep root access and complete control. No vendor lock-in.
All integration engagements begin with a 2–3 week technical audit. The audit is a paid engagement producing a gap analysis, architecture recommendation, and fixed-price statement of work.
Request audit engagementCopyright © XpertOne Security Consulting GmbH. All Rights Reserved. | Impressum | Datenschutz