Infrastructure
Firewall & VPN
Closing what has no reason to be open, and providing remote access that is not a door left ajar.
A firewall exists first to close things. The basic rule is simple: nothing is reachable from outside except what has to be, and every opening is justified by a use, documented, and reviewed from time to time. Most installations we audit have the opposite: openings nobody remembers.
A VPN answers a different need: letting somebody work remotely as though they were in the office, without exposing internal resources to the internet. It is the right answer to remote working and remote interventions, and it is also what avoids the wrong answer — opening direct access to a server.
These two do not replace the other measures. A firewall does not protect against a shared password or an opened attachment, and presenting it as a complete solution is the most common commercial shortcut in this field.
Finally, a rule that blocks work is a rule that will be circumvented. So we design what will actually be applied, even if that is slightly less strict and considerably better respected.
What we usually find
- Ports are open to the internet and nobody knows why.
- Your technician connects to the server from home, directly, unprotected.
- Remote working happens through tools installed case by case on each machine.
- Nobody has reviewed the firewall rules since it was installed.
What changes
A reduced surface
What has no reason to be reachable from outside no longer is, which removes most automated attempts.
Clean remote access
Remote work and interventions go through a named tunnel instead of an exposed direct access.
Rules you can re-read
Every opening documented with its reason, which makes it possible to close it when the reason goes away.
What you get
Closed by default
Nothing is reachable from outside except what is explicitly justified.
Documented rules
Every opening with its reason and its date, so a temporary rule does not become permanent.
Named VPN access
One access per person, revocable individually, with a second factor where possible.
Segmentation enforced
Rules between internal zones — till, cameras, workstations, guests — not only towards the outside.
Useful logging
Logs that can be consulted and are kept long enough to be useful afterwards, not only live.
Periodic review
Rules re-read at regular intervals, because a forgotten opening is the most common fault.
Is this the right fit for you?
This is for you if
- You have internal resources reachable from outside.
- People work remotely or intervene from outside the office.
- You want to know what is open and why.
This is not for you if
- You are looking for a product that solves security. None does, and a firewall does not protect against a shared password.
- You want very strict rules with no regard for how people work. They will be circumvented and you will be less protected.
- You have nothing exposed and nobody remote. This is not a priority for you.
What we commit to
Every opening is justified and dated
A rule with no written reason is a rule nobody will dare close in two years’ time.
No exposed direct access
We refuse to open a server or a recorder to the internet when a tunnel does the same job properly.
We do not present it as a complete solution
A firewall closes doors. It replaces neither named accounts, nor backups, nor updates.
What we find on arrival
Forgotten openings are the rule. An access created to fix something one day, a port opened for software no longer used, a camera made reachable from the internet so it could be watched from home: each stays for years, and none is documented. Periodic review exists precisely for that.
Improvised remote access is the second finding. A technician connecting directly to the server from home, with a password they know by heart, is a common practice and a permanent door. Replacing it with a named tunnel costs almost nothing and changes the nature of the risk.
Finally, link stability matters for VPN. A connection that drops regularly makes remote work painful, and no technical solution changes that. We measure before promising a comfortable experience.
Frequently asked questions
Is the operator’s router not enough?
For simple use, sometimes. It rarely offers internal segmentation, useful logging and named VPN access, which are precisely what distinguishes a professional installation.
Does a firewall protect us from ransomware?
Partly. Most arrives through an account or an attachment, not through an open port. The real protection is a backup out of reach, and we say so rather than leave the impression otherwise.
Does a VPN slow work down?
A little, depending on the link. Comfort depends mostly on your connection, and we measure it before promising a smooth experience.
Does each person need their own VPN access?
Yes. Shared access cannot be revoked individually, which is exactly the problem the VPN was supposed to solve.
How often should rules be reviewed?
Periodically, and always after an infrastructure change. Temporary rules become permanent by default, and that is how the exposed surface grows.
Can we manage the access ourselves?
Adding or revoking a user, yes, and we train you. Changing rules requires understanding what they protect, and we document so that it stays possible.
How to start
Tell us what is reachable from outside today, and who needs to work remotely.
We come back with the list of what is open and should not be, the remote access solution we recommend, and the rules we would apply — documented.
What we have written on this subject
Firewalls and VPNs: what goes out matters more than what comes in
What arrives unrequested is already blocked by any router. The useful half is the other one, and it is the half nobody configures.March’s temporary rule: rereading a firewall six months later
A rule added for a week is never removed. How to reread a rule set in two hours, and how to take one out without breaking anything.
Let us talk about your project
A free audit, no commitment: we look at your online presence and tell you what is holding it back.
- Every opening is justified and dated
- No exposed direct access
- We do not present it as a complete solution