Managed OPNsense firewall cluster
On this layer HOST SMITH takes over your network perimeter: a managed OPNsense firewall cluster in front of your VMs and clusters. OPNsense is the open-source firewall for rules, NAT, VPN and intrusion detection — with us always redundant: two instances in a cluster, connected via CARP IPs. If one firewall fails, the second takes over in a split second, without connections dropping.
Two management modes: open — you have access and change rules together with us, we keep the base, updates and redundancy clean. Or closed — every change runs as a service request through us, in return the ruleset is consistent, documented and audit-proof at all times. Layers 01–02 are included.
Redundancy with CARP
Two OPNsense instances share virtual IPs — failover happens automatically and without interruption, even mid-deployment.
VPN & remote access
WireGuard and IPsec for sites and employees — cleanly separated by roles, with MFA integration.
IDS/IPS & monitoring
Intrusion detection armed on request, rule hits and anomalies in monitoring — you see what's rattling at your door.
Site-to-site networking
Your locations, offices and data centers as one private network: permanent, encrypted tunnels between the firewalls — we take care of routing, failover and key rotation.
WireGuard or IPsec
WireGuard for lean, fast tunnels with modern cryptography, IPsec for remote peers that require it (corporate firewalls, older appliances) — we operate both, even in parallel.
Roadwarrior & access profiles
Employees dial in via client — split tunnel for company networks only or full tunnel for everything, configured per role, with MFA and central key revocation at offboarding.
What this layer contains.
Every layer contains all outer layers — here you see where layer 03 sits in the cosmos.
Advice that comes from the engine room.
Firewall rules accumulate like cables in a drawer. We bring order: network segmentation, zone concepts and VPN designs that survive an audit — from experience with entire company environments.
Network segmentation & zones
DMZ, app network, database network, management: we cut your networks so a compromised service doesn't open the whole house.
VPN architecture
WireGuard or IPsec, site-to-site or road warrior, split or full tunnel — we design remote access to fit team and compliance.
Audit & compliance
Ruleset review, documentation, change processes: we make your firewall ISO 27001-ready — including the evidence for it.
Calculate layer 03 now.
Firewall changes, VPN setups and similar service requests: €100 per hour plus VAT.
03 OPNsense firewall
All resources are dedicated — no overcommit.
Firewall changes, VPN setups and similar service requests: €100 per hour plus VAT.