Marvin Pascale
Network perimeter // Controlled

Firewall as a Service

NGFW · IDS · IPS · WAF

A firewall is not a one-off purchase; it is a security operating system that evolves with your network, applications, and threats. My approach prioritizes fully customizable open-source solutions, with clear policies, observability, and practical support. Where necessary, the architecture can also include proprietary enterprise platforms for specific requirements.

Core service

Tailored open source, without unnecessary compromises.

The goal is not to install a product. It is to build a perimeter aligned with your network, workloads, and risk profile. The value lies in customization and effective day-two operations.

security@perimeter:~# policy --as-code --audit-ready

Flexibility and adaptability: policies and segmentation for different environments (production, development, OT, and guest), plus VPN, VLAN/VRF, and dynamic routing integration where required.

Operational support: logging, metrics, and alerting designed for people who must respond, not simply display a dashboard. Runbooks support incident response and change control.

Scalability: standalone architectures, active/passive HA, and distributed capabilities where they make sense, including edge, data center, and branch locations.

Customization // Observability // Day two

Deep inspection

NGFW, IDS, and IPS: where the difference is made.

A modern firewall does more than filter ports. It combines inspection, detection, and prevention with application visibility and contextual controls.

NGFW and application policies

Traffic control by application and context, including segmentation, geo/IP reputation, outbound controls, and policies for critical services.

Integrated IDS / IPS

Signature, behavior, and reputation-based detection and prevention, tuned to reduce false positives and protect exposed assets.

VPN and secure access

Authenticated, auditable remote and site-to-site access with routing, split tunneling, MFA, and profile-based segregation.

WAF as an optional package

HTTP(S) application protection for portals and APIs, with rules, rate limiting, OWASP Top 10 mitigation, and dedicated observability.

Open by default

When a proprietary enterprise platform makes sense.

Open source covers a vast range of use cases. In specific scenarios, an enterprise platform may be the better choice, provided the decision is driven by requirements rather than habit.

Scenario Recommended approach Rationale
Highly prescriptive compliance environments Enterprise (targeted assessment) Certifications, vendor support, and non-negotiable formal requirements.
Proprietary capabilities required by the business Enterprise or hybrid Specific features or integrations required by existing processes.
Standard perimeter, control, and transparency Tailored open source Maximum flexibility, predictable costs, and auditable behavior.
Multiple sites and progressive growth Open source + HA design Modular scalability and an architecture shaped around actual growth patterns.

Delivery model

How to build a perimeter that lasts.

From requirements gathering to day-two operations: a process designed to reduce risk and complexity through clear, measurable decisions.

Assessment and threat modelling

Inventory, traffic flows, and objectives: what must be protected, from whom, and with what level of assurance and traceability.

Design and policy

Segmentation, rules, remote access, logging, and integration with identity and observability tools.

Implementation and hardening

Deployment, HA, IDS/IPS tuning, testing, and noise reduction, supported by clear rules and change-control procedures.

Operations and continuous improvement

Monitoring, updates, backups, and response, with KPIs and reporting that make security a stable operational function.

Handshake

Want a clear, measurable, and manageable perimeter?

Tell me about your network, sites, exposed services, and compliance requirements. I will propose a path from design through operations, using an open-source stack or an enterprise platform where it is genuinely justified.

Mastodon