Network Security
Network security with pfSense
In-segment routing, VPN termination and flexible rule authoring are configured on pfSense, forming a second inspection layer behind the hardware firewall.
- Encrypted remote access
- VPN
- Address and port forwarding
- NAT
- In-segment filtering
- Rule-based
- Traffic visibility
- Logging
Why two layers of security make sense
Relying on a single security layer means that once it is bypassed, nothing else stands in the way. So the architecture places two independent inspection points: FortiGate at the edge and pfSense within the internal segments.
pfSense's strength is flexibility. In-segment routing, address translation, port forwarding, VPN termination and detailed rule authoring all happen at this layer — including administrative access delivered through an encrypted tunnel rather than by exposing server ports to the internet.
The split is also operational: edge policies change rarely, while internal rules are updated more often as the application evolves. Keeping them in separate layers means frequent changes never touch edge security.
- Edge and internal layers stay independent
- Administrative access over an encrypted VPN
- Connectivity without exposing server ports to the internet
- Port forwarding and address translation configuration
- Traffic logs available for incident investigation
Features
Configured on the pfSense layer
VPN termination
Your team reaches servers through an encrypted tunnel, so RDP and SSH ports stay off the public internet.
In-segment routing
In multi-tier architectures, this layer decides which path traffic takes and which segments it can reach.
Detailed rule sets
Fine-grained policies are written across source, destination, port and protocol combinations.
Port forwarding (NAT)
Services exposed externally are routed through address translation so internal addressing is never revealed.
Traffic logging
Permitted and blocked connections are logged so suspicious access attempts can be reviewed later.
Restricted management access
Management interfaces are reachable only from defined sources and stay closed to the public internet.
FAQ
Frequently asked questions
How many users can VPN access be defined for?
As many as your team needs. Because access is defined per user, when someone leaves only their access is revoked — there is no need to share a common password.
Do I need to expose SSH and RDP to the internet?
We recommend against it. Left open, these ports attract constant automated password-guessing traffic. With VPN-based access the ports stay closed externally and that surface disappears entirely.
How quickly are rule changes applied?
Once the request reaches us through support, our technical team reviews and applies it. Routine changes are usually completed the same day; requests with security implications are reviewed with you first.
More
Related pages
- FirewallFortiGate firewallHardware FortiGate protection at the network edge: stateful filtering, IPS signatures, VLAN segment policies and VPN access.
- DDoS ProtectionProtection against DDoS attacksAlways-on protection against volumetric, protocol and application-layer DDoS attacks. Edge scrubbing, anomaly detection and preservation of legitimate traffic.
- Network10 Gbps isolated VLAN networkingAn isolated VLAN per customer, 10 Gbps private server-to-server networking and rule-based segment transit. Private traffic does not consume internet quota.
Let's plan your infrastructure together
Tell us what you need and we prepare a configuration and pricing specific to you. We don't sell fixed packages; we build the deployment, licensing and backup plan with you.