(434) 236-9027

Network Security

Firewalls, VPN and Network Security

Practical security for small businesses. A firewall that is actually configured, a VPN that works when someone is travelling, and a patching routine that gets followed.

Security Without the Enterprise Theater

Most businesses I work with do not need a security operations center. They need a firewall whose rules somebody has read this decade, a VPN that works from a hotel, a network where the guest wifi cannot reach the accounting server, and a patch cadence that is written down instead of remembered. That list is short and unglamorous, and it closes the most common network-level paths in. It does not close phishing or a stolen password, which is why the patch cadence and the segmentation matter as much as the firewall.

I build and maintain that layer. Barracuda firewall configuration and rule review, site-to-site and remote-access VPN, VLAN segmentation, SSH hardening, fail2ban, TLS certificates, and a patching schedule with an owner. I work across Windows and Linux, on site in Central Virginia and remotely for clients nationwide.

I am a solo operator, so you talk to the person doing the work. There is no tier-one queue between you and the change you asked for, and nobody is trying to sell you a platform you will never log into.

BarracudaWireGuardIPsecOpenVPNVLANfail2bannftablesOpenSSHLet's Encrypt

Barracuda Firewall Configuration

A firewall is only as good as the rules on it, and on most small-business appliances those rules were written once during install and never touched again.

The pattern I find over and over: a permit-any outbound rule, RDP or SSH forwarded straight from the whole internet to a server, and a rule set nobody can read because the network objects were never named. The box is doing its job perfectly. It is just being asked to allow everything.

On a Barracuda I rebuild the rule set around named network and service objects so each rule reads like a sentence, replace any-to-any port forwards with source-restricted access or remove the forward entirely and put the service behind the VPN, move application control and IPS profiles out of permanent monitor mode, and set up log forwarding so there is a record when you need one.

Then the boring items that break at the worst possible moment: firmware level, license and subscription expiry dates, whether the config backup exists and is current, and whether the failover or link balancing you are paying for has ever been tested. A high-availability pair that has never failed over is a guess, not a plan.

Site-to-Site and Remote-Access VPN

Two different problems that get called the same thing, and they fail in completely different ways.

Site-to-site joins offices, or joins an office to a colocation or cloud environment, so systems talk privately over a fixed tunnel. I build these with IPsec where both ends are appliances, and with WireGuard where one end is a Linux server or a VPS. Routing and overlapping subnets are where these quietly fail. If both sites use 192.168.1.0/24 the tunnel will come up green and nothing will actually reach anything, so address planning comes before configuration.

Remote access is for people, not sites. The rule I hold to is that a remote user should not land on the flat office network. They land in their own address range which is then permitted to reach the specific systems that role needs, so a compromised home laptop does not inherit the entire LAN. WireGuard when I want speed and simple key management, or the client VPN already licensed on the Barracuda when users want a supported installer.

Certificate or key-based authentication rather than a shared password on a sticky note. MFA where the platform supports it. And a written offboarding step, because the account nobody remembers to revoke is the one that eventually gets used.

What Is Included

Network Segmentation

VLANs separating guest wifi, VoIP handsets, cameras and IoT, workstations, and servers. Inter-VLAN traffic is written as explicit permits rather than assumed. Guest gets internet and nothing else.

SSH Hardening

Key-only authentication, password auth disabled, root login off, AllowUsers or AllowGroups scoped to real accounts, and where the host is not public-facing, SSH reachable only from the VPN range.

fail2ban and Rate Limiting

Jails for sshd plus web and mail services where they run, sane ban and find windows, and office and VPN ranges whitelisted so a fat-fingered password does not lock you out of your own server.

Patching Discipline

A monthly cadence covering operating systems, firewall firmware, and hypervisors. Unattended security updates on Linux, an agreed reboot window, and a written record of what is running which version.

TLS and Certificates

Let's Encrypt with automated renewal, and renewal that is monitored rather than trusted. Internal tools go behind the VPN instead of being published with a self-signed certificate everyone has learned to click past.

Logging and Alerting

A central destination for firewall and server logs, retention long enough to be useful during an incident, and alerts scoped to events worth waking up for instead of a mailbox nobody opens.

Backups You Can Restore

Security and backup are the same conversation once ransomware is on the table. An offsite copy that is not reachable with domain credentials, and at least one restore that has actually been performed.

Access Review

Who holds admin, which logins are shared between people, what is still enabled for someone who left last year, and which vendor has a standing account nobody has audited since installation day.

How an Engagement Runs

01

Find Out What Is There

I read the live firewall rules, map the network as it exists rather than as the diagram claims, list everything answering from the internet, and check patch levels and admin access. Nothing is changed in this phase.

02

Close the Exposures First

Internet-facing holes get shut before anything else, in priority order. Segmentation and VPN work follows, scheduled around your hours so no one loses a working day to a change they were not told about.

03

Keep It That Way

Patch cadence, periodic log and rule review, license and certificate expiry tracking, and documentation of the network as built so the next person is not starting from a blank page.

If you only want the first step, that is a fine place to stop. A written picture of what is exposed is useful on its own.

Proof This Is Real Work

Infrastructure I Run Daily

The network, hypervisors, servers, and git-driven deployment workflow behind my own operation, including the firewall rules, VPN tunnels, and mirrored backup targets that sit underneath it.

BarracudaProxmoxVPNSynology
View Details →

Server Builds

Linux and Windows server deployment where hardened SSH, firewall rules, automated backups, and monitoring are part of the build rather than a follow-up project nobody funds.

nginxsystemdDockerCloudPanel
View Details →

Need Your Network Locked Down?

Tell me what you are running now and what keeps breaking. A 24 hour answering service picks up and routes straight to my cell when something is down; scheduled work happens in agreed windows. I am based in Lynchburg, onsite across Central Virginia, and remote for clients nationwide.

Get in Touch
Mr. Botsworth

Mr. Botsworth

Hey! I'm Mr. Botsworth, Greg's search bot. Ask me about his projects, skills, or services.