Remote for Germany

Network administration, firewalls and VPN

Networking has been my specialty since the Cisco Networking Academy: I administer core routers, enterprise switches from Dell and Arista, hardware firewalls and OPNsense systems and operate an own autonomous system with BGP connectivity and own IP space for KernelHost GmbH. Add to that experience in mitigating large DDoS attacks and analysing faults that others consider inexplicable.

For companies I design and operate networks that are cleanly segmented, documented and secured: from the site network with VLANs and Wi-Fi to connecting several sites and data centres via VPN.

What is included

  • Network design and documentation: IP concepts for IPv4 and IPv6, VLANs, segmentation, address management
  • OPNsense and pfSense: setup, rule sets, IDS/IPS, high availability with CARP, VPN gateways
  • Site-to-site and client VPN with WireGuard, IPsec and OpenVPN including two-factor authentication
  • Configuration of enterprise switches (Dell OS9/OS10, Arista, Cisco, MikroTik, UniFi) with redundancy and MLAG
  • Routing protocols, BGP connectivity, own IP space, RPKI and peering questions
  • Troubleshooting with packet captures, flow data and monitoring, even for sporadic faults
  • DDoS protection concepts in cooperation with KernelHost GmbH
  • Network monitoring with SNMP, sFlow and Grafana dashboards

Typical assignments

  • A company with two sites gets a redundant OPNsense firewall and a WireGuard VPN between the sites.
  • Sporadic packet loss in a data centre network is traced back to an MLAG problem and fixed.
  • A flat network is split into VLANs for office, servers, guests and IoT without interrupting operations.
  • A hosting provider gets support with BGP connectivity and own IP space.

Process

  1. Request

    Describe your needs briefly via the form, WhatsApp or the live chat.

  2. Assessment

    Within one business day you receive an assessment with effort, price and a proposed date.

  3. Implementation

    I do the work personally, remotely via secured access or on site, and keep you updated throughout.

  4. Handover and invoice

    Documented handover, then an invoice from KernelHost GmbH with convenient payment via kernelhost.com.

Questions about this service

Which firewall do you recommend for small and medium-sized companies?

OPNsense on suitable hardware offers enterprise features without licence costs: rule sets, VPN, IDS/IPS and high availability. If vendor support is desired, I advise neutrally on alternatives.

Can you analyse faults remotely as well?

Yes, via secured access to firewall, switches and an analysis system. For measurements on site in Vienna I come by personally.

Do you support IPv6?

Of course. I plan every new network with IPv4 and IPv6 and extend existing networks step by step.

Remote for companies across Germany, alignment via video call, ticket or chat.

Ready to discuss your project?

Describe your project in a few sentences. You will receive an assessment with effort and price within one business day.