Skip to content

Network Security

Network security with pfSense

In-segment routing, VPN termination and flexible rule authoring are configured on pfSense, forming a second inspection layer behind the hardware firewall.

Encrypted remote access
VPN
Address and port forwarding
NAT
In-segment filtering
Rule-based
Traffic visibility
Logging

Why two layers of security make sense

Relying on a single security layer means that once it is bypassed, nothing else stands in the way. So the architecture places two independent inspection points: FortiGate at the edge and pfSense within the internal segments.

pfSense's strength is flexibility. In-segment routing, address translation, port forwarding, VPN termination and detailed rule authoring all happen at this layer — including administrative access delivered through an encrypted tunnel rather than by exposing server ports to the internet.

The split is also operational: edge policies change rarely, while internal rules are updated more often as the application evolves. Keeping them in separate layers means frequent changes never touch edge security.

  • Edge and internal layers stay independent
  • Administrative access over an encrypted VPN
  • Connectivity without exposing server ports to the internet
  • Port forwarding and address translation configuration
  • Traffic logs available for incident investigation

Features

Configured on the pfSense layer

  • VPN termination

    Your team reaches servers through an encrypted tunnel, so RDP and SSH ports stay off the public internet.

  • In-segment routing

    In multi-tier architectures, this layer decides which path traffic takes and which segments it can reach.

  • Detailed rule sets

    Fine-grained policies are written across source, destination, port and protocol combinations.

  • Port forwarding (NAT)

    Services exposed externally are routed through address translation so internal addressing is never revealed.

  • Traffic logging

    Permitted and blocked connections are logged so suspicious access attempts can be reviewed later.

  • Restricted management access

    Management interfaces are reachable only from defined sources and stay closed to the public internet.

FAQ

Frequently asked questions

How many users can VPN access be defined for?

As many as your team needs. Because access is defined per user, when someone leaves only their access is revoked — there is no need to share a common password.

Do I need to expose SSH and RDP to the internet?

We recommend against it. Left open, these ports attract constant automated password-guessing traffic. With VPN-based access the ports stay closed externally and that surface disappears entirely.

How quickly are rule changes applied?

Once the request reaches us through support, our technical team reviews and applies it. Routine changes are usually completed the same day; requests with security implications are reviewed with you first.

Let's plan your infrastructure together

Tell us what you need and we prepare a configuration and pricing specific to you. We don't sell fixed packages; we build the deployment, licensing and backup plan with you.