PFSENSE
Design and implementation of pfSense platforms for secure firewall and routing services
What we implement
- Advanced Firewall and NAT : Network/VLAN/User Policies, GeoIP, White/Black Lists.
- Routing and segmentation : 802.1Q VLAN, inter-VLAN, static routes, policy-based routing.
- High Availability (HA) : CARP + pfsync for active/passive failover, rule and state synchronization.
- Multi-WAN : balancing and failover (fiber, LTE/5G, Starlink), gateway groups with health checks.
- Enterprise VPNs : IPsec (IKEv2) , OpenVPN , and WireGuard for site-to-site and remote access (MFA).
- QoS/Traffic Shaping : limiters, FQ-CoDel to prioritize voice, video conferencing and critical systems.
- IDS/IPS : Suricata/Snort with updated rules and detection/prevention modes.
- DNS and DHCP : Unbound (DNS resolver/forwarder), DNS-over-TLS, split-DNS, static DHCP per MAC.
- Captive portal : vouchers, RADIUS/LDAP/AD integration for guest WiFi.
- Certificates : Automated ACME/Let's Encrypt.
- Observability : remote syslog, NetFlow/softflowd, Zabbix agent, mail/Telegram alerts.
- Hardening and backups : hardening, encrypted backups, and fast restore.